validation-agent

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill acts as a procedural guide and does not contain any functional code, shell commands, or network operations. It focuses on the creation and management of documentation files related to system validation.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external inputs such as user needs and stakeholder statements to generate validation plans. While this represents an ingestion surface for potentially untrusted data, the agent lacks high-risk capabilities (like network exfiltration or system commands) to execute malicious instructions embedded in that data. * Ingestion points: Reads approved intended-use statements, user needs, and verification results (SKILL.md). * Boundary markers: None identified. * Capability inventory: Restricted to creating and updating local documentation files (VALIDATION_PLAN.md, VALIDATION_PROTOCOL.md, VALIDATION_REPORT.md, AI_RUN_MANIFEST.yaml). * Sanitization: No explicit sanitization or filtering of external content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 06:07 AM
Security Audit — agent-trust-hub — validation-agent