to-questionnaire

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs legitimate productivity tasks, converting conversation into a structured Markdown document. All requested tools (Read, Grep, Glob, Write) are appropriate for the defined scope of managing files and documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from user responses to generate a document.
  • Ingestion points: User input collected during the "Who is it going to?" and "What do you need back?" interview phases.
  • Boundary markers: Employs a specific Markdown template with headers and blockquotes to structure the output.
  • Capability inventory: Uses the Write tool to create a local file named to-questionnaire-<slug>.md.
  • Sanitization: No explicit sanitization of user input is documented, but the output is intended for human review and asynchronous communication rather than automated execution.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 02:14 PM
Security Audit — agent-trust-hub — to-questionnaire