skills/dzhng/skills/explore-unknowns/Gen Agent Trust Hub

explore-unknowns

Pass

Audited by Gen Agent Trust Hub on Oct 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted data by scanning the user's local "territory" (codebase) and sweeping every file relevant to a task to identify unknowns and landmines.
  • Ingestion points: Untrusted content enters the agent's context during the scanning phase described in references/stage-1-known-knowns.md ("scan the territory") and the systematic file sweep described in references/stage-4-unknown-unknowns.md ("Sweep every file the task touches").
  • Boundary markers: The instructions do not provide explicit boundary markers or delimiters (such as XML tags or triple backticks with warnings) to prevent the agent from accidentally following instructions embedded within the files being scanned.
  • Capability inventory: The skill leverages file-reading and subagent analysis capabilities. It does not explicitly include instructions for file-writing, network operations, or arbitrary command execution based on the scanned content.
  • Sanitization: There is no evidence of sanitization, escaping, or filtering of the external content before it is processed by the agent or interpolated into planning responses.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 4, 2026, 03:45 PM
Security Audit — agent-trust-hub — explore-unknowns