ml-engineer

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is a set of guidelines and instructions for acting as an ML engineer. No patterns associated with prompt injection, credential theft, or unauthorized network operations were found.
  • [NO_CODE]: This skill package contains only markdown documentation. There are no executable scripts, binaries, or configuration files that would perform operations on the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions include a reference to an external implementation playbook, which represents a potential ingestion surface for untrusted data.
  • Ingestion points: Instruction to open resources/implementation-playbook.md (SKILL.md).
  • Boundary markers: None identified; no specific delimiters are defined to separate the agent's instructions from the playbook content.
  • Capability inventory: No scripts or tool execution logic are included in the skill body.
  • Sanitization: No validation or sanitization instructions are provided for the content within the referenced file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:16 PM
Security Audit — agent-trust-hub — ml-engineer