availability-heuristic

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to elicit and analyze user-provided risk estimates, which creates a standard surface for indirect prompt injection where untrusted data enters the agent's context.
  • Ingestion points: User input is requested during the 'Coach mode' and 'The Process' sections in SKILL.md.
  • Boundary markers: The instructions do not define specific delimiters to separate user data from agent instructions.
  • Capability inventory: The skill consists entirely of markdown files and contains no executable scripts or tool-invocation permissions.
  • Sanitization: No input validation or filtering is specified.
  • [EXTERNAL_DOWNLOADS]: The skill references several external resources for data and methodology.
  • Fetches base-rate data from official reports by well-known organizations including the Stanford Institute for Human-Centered AI (HAI), the OECD, and the International Labour Organization (ILO).
  • Provides links to the vendor's official website (deciqai.com) and GitHub repository (github.com/deciqai) for documentation and updates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:14 AM
Security Audit — agent-trust-hub — availability-heuristic