ai-agent-builder

Pass

Audited by Gen Agent Trust Hub on Jul 8, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill serves as a guide for AI agent design and contains no malicious code or instructions. External references point to well-known services.
  • [NO_CODE]: The skill contains no executable scripts or binary files, consisting solely of Markdown documentation and YAML configurations.
  • [PROMPT_INJECTION]: The skill outlines architectures where agents process untrusted data (e.g., messages, documents) and use tools with external side effects. This documents an inherent attack surface for indirect prompt injection. 1. Ingestion points: SKILL.md (Slack/Telegram message ingestion). 2. Boundary markers: Absent from the example templates. 3. Capability inventory: web_search, database_query, send_email, code_interpreter (referenced in SKILL.md). 4. Sanitization: Not addressed in the architectural examples.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 8, 2026, 07:46 PM
Security Audit — agent-trust-hub — ai-agent-builder