skills/alvindean/soniq/context-engine/Gen Agent Trust Hub

context-engine

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is primarily a set of guidelines and instructions for the agent on how to handle data safely. It explicitly forbids the exfiltration of sensitive identifiers and financial data.
  • [NO_CODE]: No executable scripts or binary files are included in the skill, significantly reducing the attack surface for traditional remote code execution or persistence mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests data from a local file (~/.claude/company-context.md), it includes robust mitigation measures. Evidence:
  • Ingestion points: Local context file identified in SKILL.md (Step 1
  • Load Protocol).
  • Boundary markers: No explicit delimiter instructions are provided for the context file content.
  • Capability inventory: The skill instructions reference external tool use and web searches (references/anonymization-protocol.md).
  • Sanitization: Implements a comprehensive anonymization protocol (references/anonymization-protocol.md) that transforms absolute financial figures and specific names into generic descriptors before any external transmission.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 01:32 PM