skills/aseeon/just-skills/just-scope/Gen Agent Trust Hub

just-scope

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill facilitates legitimate requirement scoping and documentation tasks. It utilizes repository analysis to ground feature requests in existing code and documentation, with no evidence of malicious patterns, network exfiltration, or persistence mechanisms detected.\n- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection because it is designed to ingest and analyze external content from the repository, although this is inherent to its primary purpose.\n
  • Ingestion points: The agent is instructed to read instructions, relevant documentation, code, and tests from the current repository (SKILL.md Section 1).\n
  • Boundary markers: While the instructions emphasize reading only relevant content and citing evidence, there are no explicit delimiters or specific warnings for the agent to ignore instructions embedded within those files.\n
  • Capability inventory: The skill allows the agent to read repository files and write documentation to the docs/ folder.\n
  • Sanitization: No specific mechanisms for sanitizing or filtering repository content are defined within the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 01:36 PM
Security Audit — agent-trust-hub — just-scope