vendored-assets

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown documentation defining a workflow for asset management. It does not include any scripts, binaries, or automated tool configurations.
  • [INDIRECT_PROMPT_INJECTION]: The skill describes a process for handling external supply-chain inputs (artifacts) which could theoretically contain malicious instructions. Ingestion points: Third-party artifacts like JavaScript and CSS files (SKILL.md). Boundary markers: The workflow explicitly requires an 'Audit the complete diff' step to identify suspicious content. Capability inventory: No executable capabilities, subprocess calls, or network operations are present in the skill files. Sanitization: The skill mandates manual or agent-led verification of provenance and behavior before accepting assets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 10:08 AM