general-purpose

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill defines a research-to-action workflow that processes information from untrusted external sources and executes tasks using system-level capabilities, establishing an indirect prompt injection surface.
  • Ingestion points: The agent is instructed to gather data from documentation, web resources, and GitHub repositories as detailed in SKILL.md.
  • Boundary markers: There are no instructions for using delimiters or boundary markers to isolate instructions found within external data.
  • Capability inventory: The agent is authorized to use bash for system operations and various file manipulation tools for task execution.
  • Sanitization: The methodology lacks requirements for data validation or sanitization of content retrieved from external sources.
  • [NO_CODE]: The skill consists entirely of instructional markdown and does not include any accompanying scripts, executables, or code files.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 08:31 AM
Security Audit — agent-trust-hub — general-purpose