okr-builder
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill functions as a static prompt template for goal setting. It does not contain any executable scripts, shell commands, or external dependencies.
- [SAFE]: Analysis of the YAML frontmatter and skill body shows no requests for restricted tools or elevated privileges. The skill scope is limited to structured text output.
- [INDIRECT_PROMPT_INJECTION]: The skill accepts user-supplied data in the
[CURRENT SITUATION]field. However, because the skill has no tool-calling capabilities, file system access, or network permissions, there is no attack surface for malicious instructions to exploit.
Audit Metadata