nerd-monitor
Pass
Audited by Gen Agent Trust Hub on Aug 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of markdown instructions and YAML configuration. No executable scripts, shell commands, or network-enabled tools are defined or requested.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external processes or state sources. While this establishes an ingestion point for potentially untrusted data, the risk is minimized by the skill's explicit instruction to remain in a non-mutating state.
- Ingestion points: External 'relevant state sources' defined during the Monitor routine.
- Boundary markers: The instructions do not specify explicit delimiters for external data.
- Capability inventory: The skill does not define any subprocess, file-write, or network operations.
- Sanitization: No specific sanitization or filtering is described, but the instructions strictly prohibit modifying external state.
Audit Metadata