threat-modeling

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes an explicit 'Prompt Injection Safety Notice' in Section 8. While this section contains phrases like 'ignore previous instructions', they are used defensively to instruct the agent to disregard such commands if found within analyzed data.
  • [DATA_EXFILTRATION]: The skill does not request or use network-enabled tools. All analysis is performed on provided system documentation without external data transfer.
  • [COMMAND_EXECUTION]: The agent is limited to read-only tools for file analysis (Read, Grep, Glob). No administrative commands, shell execution, or persistence mechanisms are present.
  • [SAFE]: The skill is analytical in nature, adheres to the principle of least privilege, and includes explicit instructions for the redaction of sensitive findings during analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 02:11 PM
Security Audit — agent-trust-hub — threat-modeling