social-engineering-awareness

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses the capability to ingest and analyze potentially untrusted data from the codebase and filesystem, constituting an indirect prompt injection surface.
  • Ingestion points: Data is ingested via the codebase and filesystem tools for tasks such as training needs analysis, simulation results analysis, and vulnerability findings (SKILL.md).
  • Boundary markers: The skill does not define explicit delimiters or instructions to ignore embedded commands within the ingested assessment data.
  • Capability inventory: The skill utilizes the codebase and filesystem tools, which may include file-write capabilities depending on the environment configuration.
  • Sanitization: The instructions do not specify any methods for sanitizing, validating, or escaping external content before it is interpolated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 11:03 AM
Security Audit — agent-trust-hub — social-engineering-awareness