skills/cursor/plugins/bro/Gen Agent Trust Hub

bro

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides instructions for the agent to restate its last message in plain, jargon-free language. No malicious patterns, network requests, or sensitive file accesses were detected.
  • [SAFE]: The skill configuration includes disable-model-invocation: true, which acts as a security constraint by preventing the agent from calling tools or making further model invocations during the execution of these instructions.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process the 'last message' (ingestion point: conversation history). While there are no explicit boundary markers or sanitization steps, the capability inventory is empty because tool and model usage are disabled in the frontmatter, preventing any potentially injected instructions from triggering dangerous actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 07:20 AM
Security Audit — agent-trust-hub — bro