alterlab-nmc-digital-ethics

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core workflow of processing untrusted external data.
  • Ingestion points: The agent is instructed to 'Read existing project files' and 'search the web' for ethical frameworks, policies, and case studies (SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters or specific warnings to ignore instructions embedded within the processed project files or web content.
  • Capability inventory: The skill possesses the ability to perform web searches, read local files, and write new markdown files to the project directory (SKILL.md).
  • Sanitization: There is no mention of sanitizing or validating the content retrieved from external sources or files before it is used to generate new deliverables.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 11:44 PM
Security Audit — agent-trust-hub — alterlab-nmc-digital-ethics