events

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to read local context files, such as .agents/product-marketing.md, to inform its responses. This establishes a surface for indirect prompt injection if those files were to be populated with untrusted data.\n
  • Ingestion points: References to .agents/product-marketing.md, .claude/product-marketing.md, and product-marketing-context.md in SKILL.md.\n
  • Boundary markers: No specific delimiters or safety instructions are defined for processing the content of these files.\n
  • Capability inventory: The skill is primarily instructional and does not utilize dangerous tools such as shell execution, network exfiltration, or unauthorized file modifications.\n
  • Sanitization: No sanitization or content validation is implemented for the ingested context files.\n- [SAFE]: No malicious patterns, such as hardcoded credentials, remote code execution (e.g., piped shell commands), persistence mechanisms, or obfuscated payloads, were found across the skill files. The external GitHub references are legitimate attributions for methodology and do not represent automated execution risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 10:02 PM
Security Audit — agent-trust-hub — events