reduce-system-complexity
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from the local environment which could potentially contain malicious instructions.
- Ingestion points: The skill analyzes existing implementation code, test suites, system traces, history, and operator knowledge (SKILL.md).
- Boundary markers: The instructions mandate redacting secrets and tokens from reports, but do not specify the use of delimiters for untrusted input (SKILL.md).
- Capability inventory: The skill is capable of reading files, generating reports, and performing authorized code modifications (SKILL.md).
- Sanitization: Includes a mandatory redaction policy for sensitive information in generated outputs (SKILL.md).
- [EXTERNAL_DOWNLOADS]: The skill references external source code for attribution and documentation purposes.
- Evidence: The skill provides links to the original source repository on GitHub (references/source-notes.md, LICENSE).
Audit Metadata