skills/broomva/skills/checkit/Gen Agent Trust Hub

checkit

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [PROMPT_INJECTION]: The skill explicitly overrides standard agent behavior by mandating autonomy and suppressing clarifying interactions. Instructions include 'Never ask "what do you want me to do with this?"' and 'Asking is the failure this skill exists to kill' (SKILL.md), while the 'no-ask-back contract' in the lens reference enforces this as a core invariant (references/checkit-lens.md).
  • [PROMPT_INJECTION]: The skill presents a high surface for indirect prompt injection by design. \n
  • Ingestion points: Reads arbitrary artifacts including URLs, repositories, papers, and images (SKILL.md). \n
  • Boundary markers: Absent. The skill lacks instructions to delimit external content or to ignore potential instructions embedded within artifact data. \n
  • Capability inventory: The skill utilizes tools to read workspace state (branches, PRs), perform network research, and proactively update local knowledge bases without user permission (SKILL.md). \n
  • Sanitization: Absent. Although URL verification is mentioned to prevent hallucinations, there is no validation or sanitization of content extracted from artifacts (SKILL.md).
  • [DATA_EXFILTRATION]: The automated 'Contextualize' step reads active workspace information, such as current branches and open PRs (SKILL.md). The combination of autonomous project data access, network fetch capabilities, and a policy of suppressing user confirmation creates a potential risk for data exposure if the agent is manipulated by instructions in a malicious artifact.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 03:03 PM
Security Audit — agent-trust-hub — checkit