and-clarify
Pass
Audited by Gen Agent Trust Hub on Jul 13, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection surface as it ingests untrusted work records and state reasons from a configured backend (ingestion points in SKILL.md). While explicit boundary markers for ingested text are not defined, the skill mitigates risks through a mandatory human-in-the-loop confirmation step ('shared-understanding confirmation') and by delegating interview logic to a specific authoritative skill ('grilling').- [DATA_EXFILTRATION]: The skill writes session state to a local recovery buffer and synchronizes resolved decisions to a user-configured backend. These operations are essential to the skill's primary function and are performed using a deterministic path in the user's temporary directory and a dedicated backend contract tool.- [COMMAND_EXECUTION]: No shell command execution, subprocess spawning, or dynamic script execution patterns were detected in the provided files.
Audit Metadata