skills/dzhng/jevgrep/explore-unknowns/Gen Agent Trust Hub

explore-unknowns

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes external codebase files during the 'Scan' and 'Sweep' phases, which serves as a potential surface for indirect prompt injection from malicious content within those files. * Ingestion points: The agent reads local files in the target project directory (referenced in stage-1-known-knowns.md and stage-4-unknown-unknowns.md). * Boundary markers: No specific delimiters or 'ignore instructions' warnings are defined for the file-reading process. * Capability inventory: The skill uses file-read tools and spawns subagents to process the codebase. * Sanitization: The skill relies on the underlying model's safety protocols for processing untrusted text.
  • [SAFE]: The skill enforces a security policy for generated HTML artifacts, requiring them to be self-contained with inline assets and no external network requests, which mitigates data exfiltration risks.
  • [SAFE]: The 'Preference Checkpoint' delegation system requires explicit user opt-in and provides full disclosure for every decision made by the agent, ensuring user oversight and preventing unauthorized autonomous actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 02:29 PM
Security Audit — agent-trust-hub — explore-unknowns