review

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No security concerns detected. The skill uses restricted plugin tools to manage application-specific data. It does not perform network operations, access sensitive files, or execute arbitrary code.
  • [PROMPT_INJECTION]: The skill has an indirect prompt injection surface because it processes data from external sources (e.g., bulk imports).
  • Ingestion points: Captured data and revisions are retrieved via mcp__plugin_origin_origin__list_pending and mcp__plugin_origin_origin__list_pending_revisions tools in SKILL.md.
  • Boundary markers: The instructions do not define boundary markers or clear encapsulation for external content processing.
  • Capability inventory: Capabilities are limited to confirm, forget, capture, accept, and dismiss operations via the plugin's MCP tools.
  • Sanitization: No sanitization or filtering is performed on the records before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 07:52 AM
Security Audit — agent-trust-hub — review