review
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No security concerns detected. The skill uses restricted plugin tools to manage application-specific data. It does not perform network operations, access sensitive files, or execute arbitrary code.
- [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes data from external sources (e.g., bulk imports).
- Ingestion points: Captured data and revisions are retrieved via
mcp__plugin_origin_origin__list_pendingandmcp__plugin_origin_origin__list_pending_revisionstools in SKILL.md. - Boundary markers: The instructions do not define boundary markers or clear encapsulation for external content processing.
- Capability inventory: Capabilities are limited to confirm, forget, capture, accept, and dismiss operations via the plugin's MCP tools.
- Sanitization: No sanitization or filtering is performed on the records before the agent processes them.
Audit Metadata