buildbetter-smart-tags
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external 'evidence sources' and 'target objects' to evaluate and classify them using Smart Tags. This presents an attack surface where malicious instructions could be embedded in the data being classified.
- Ingestion points: Data is ingested from external 'evidence sources' and defined via 'inclusion and exclusion rules' mentioned in
SKILL.md(Workflow Step 2). - Boundary markers: The workflow mitigates this by requiring the agent to restate rules and for the user to 'review every prediction' (Step 7) and provide 'exact approval' (Safety Contract) before publishing.
- Capability inventory: The skill uses tools to draft, evaluate, and publish tags (
create-smart-tag-draft,run-smart-tag-evaluation,publish). - Sanitization: The instructions emphasize 'manual review' and 'approval gates' as the primary controls rather than automated sanitization.
- [SAFE]: The skill implements a robust safety contract that restricts mutations to 'exact approval' and prohibits bypassing standard tool paths (e.g., via GraphQL). It also ensures sensitive data like secrets are not included in idempotency keys.
Audit Metadata