naval-perspective
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is primarily composed of natural language instructions and philosophical frameworks intended to guide the agent's reasoning and communication style.
- [INDIRECT_PROMPT_INJECTION]: The skill uses a 'WebSearch' tool to retrieve real-world data to support its responses. This ingestion of external data constitutes a potential attack surface for indirect prompt injection, but the skill implements this as a core feature for accuracy rather than as a vector for malicious behavior. No evidence of malicious exploitation was found.
- [COMMAND_EXECUTION]: The documentation mentions installation via
npx skills add. This is a user-facing command for the 'Agent Skills' platform and is not an instruction for the agent to execute shell commands autonomously.
Audit Metadata