gandalf-ctf
Pass
Audited by Gen Agent Trust Hub on Jul 2, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill communicates with Lakera's official API (
gandalf-api.lakera.ai) to participate in the Gandalf CTF challenge. Lakera is a well-known security technology company. - [DATA_EXFILTRATION]: API interactions use a standard bearer token obtained via a registration endpoint. There is no evidence of the skill accessing or exfiltrating sensitive local files, credentials, or environment variables.
- [PROMPT_INJECTION]: Although the skill involves exploring prompt injection techniques against game targets, its own instructions do not attempt to override the AI agent's core behavior, bypass safety constraints, or extract system prompts.
- [NO_CODE]: The skill provides structured instructions for API interactions and does not include any executable scripts, binaries, or third-party dependencies.
Audit Metadata