finding-unknowns
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The instructions utilize structural markers like 'Global rule' and 'Scope rule' to define the logic of the quadrant walk; these are benign instructional constraints and do not attempt to override model safety filters.
- [COMMAND_EXECUTION]: The skill makes use of codebase search and subagent invocation to gather context about the project 'territory'. These actions are essential to the skill's function as an analysis tool and occur within the agent's provided environment.
- [DATA_EXFILTRATION]: The skill explicitly mandates that all generated HTML artifacts must be self-contained with no external requests, effectively mitigating common exfiltration vectors through generated content.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface by reading files from the user's codebase. However, it incorporates citations and requires verification of claims against the 'territory', which limits the risk of following malicious instructions embedded in the analyzed code.
Audit Metadata