automation-shape-routing
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [SAFE]: No security issues were identified. The skill is purely instructional and limits its own scope to providing a string-based routing decision.\n- [INDIRECT_PROMPT_INJECTION]: The skill processes external task intents to generate a routing verdict. While this represents a potential input surface for indirect instructions, the skill possesses no capabilities (such as network or file access) that could be misused, and the output is strictly validated against a predefined schema.\n
- Ingestion points: Reads
task-intentfrom the agent's execution context inSKILL.md.\n - Boundary markers: No explicit delimiters or safety instructions are used to wrap the input data.\n
- Capability inventory: No subprocess calls, file operations, or network requests were identified across the skill.\n
- Sanitization: No sanitization is applied to the input intent.\n- [COMMAND_EXECUTION]: The documentation includes a bash snippet using
awkto validate the output format of the routing verdict. This script is intended for formatting verification and does not perform any dangerous operations or interact with system resources.
Audit Metadata