fact-checking-explainers

Pass

Audited by Gen Agent Trust Hub on Jul 10, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it is designed to ingest and analyze untrusted content from external URLs and local codebase files to verify claims.
  • Ingestion points: Processes content from external source URLs, local files (for codebase verification), and draft explainer text provided as input.
  • Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore' instructions to isolate untrusted data from the agent's core logic.
  • Capability inventory: The skill utilizes file and URL read capabilities to perform its task. There is no evidence of subprocess execution, file writing, or data exfiltration logic.
  • Sanitization: Absent. No methods for validating, escaping, or filtering retrieved content are mentioned in the instructions.
  • [NO_CODE]: The skill is composed strictly of Markdown instructions and YAML configuration files. It does not include executable scripts (Python, JavaScript), binaries, or automation scripts, which minimizes its direct attack surface compared to skills with executable components.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 10, 2026, 12:17 PM
Security Audit — agent-trust-hub — fact-checking-explainers