voltage-effect

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown documentation (SKILL.md, example files, and references). It does not include any executable scripts (e.g., Python, Node.js, or Shell) or automation logic.
  • [PROMPT_INJECTION]: The skill defines a process for ingesting user data to generate a 'Voltage Diagnosis' report, which constitutes an indirect prompt injection surface.
  • Ingestion points: User input regarding business pilot results, sample sizes, and scaling plans is requested in SKILL.md under 'Coach mode' and 'The Process'.
  • Boundary markers: The output template 'Voltage Diagnosis' in SKILL.md does not use specific delimiters to separate user-supplied strings from internal instructions.
  • Capability inventory: The skill identifies no active capabilities; it specifies no tools in the frontmatter and contains no code that would allow for file system access, network operations, or command execution.
  • Sanitization: No sanitization or input validation logic is present in the instructional text.
  • [SAFE]: All external links point to official vendor resources (deciqai.com), academic institutions (aeaweb.org), research organizations (nber.org), or government filings (sec.gov). These references are used solely for educational documentation and do not involve remote code execution or data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:15 AM
Security Audit — agent-trust-hub — voltage-effect