alterlab-pra-csr-designer
Pass
Audited by Gen Agent Trust Hub on Apr 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns detected. The skill follows its stated purpose of assisting in CSR and social impact campaign design using standard web search and file writing tools.
- [PROMPT_INJECTION]: The skill defines a specific persona and autonomous workflow (e.g., "You operate as an autonomous agent"), which is standard for specialized agent skills. No instructions were found that attempt to bypass AI safety filters or override system-level constraints.
- [DATA_EXFILTRATION]: While the skill includes capabilities to read project files and perform web searches, these are used for the intended purpose of auditing brand values and researching social impact data. No exfiltration to unknown external endpoints or suspicious file-read-then-send patterns were identified.
- [REMOTE_CODE_EXECUTION]: No patterns for remote script execution (e.g., curl|bash), package installations, or dynamic code generation were detected.
- [COMMAND_EXECUTION]: The skill does not execute arbitrary shell commands or attempt privilege escalation via sudo or similar tools.
- [DATA_EXFILTRATION]: The skill presents an indirect prompt injection surface (Category 8) due to its core functionality:
- Ingestion points: The skill reads external project files and web search results (SKILL.md).
- Boundary markers: Absent; no explicit delimiters or instructions to ignore embedded commands in ingested data are used.
- Capability inventory: The skill can search the web, read files, and write markdown files (SKILL.md).
- Sanitization: Absent; no explicit validation or filtering of ingested external content is described. This is noted as a standard surface for document-processing skills and does not indicate malicious intent.
Audit Metadata