endor-explain

Pass

Audited by Gen Agent Trust Hub on Mar 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions and templates are consistent with its stated purpose of explaining security findings. It utilizes vendor-controlled tools (get_endor_vulnerability, check_dependency_for_risks, get_resource) and domains (app.endorlabs.com) without any signs of malicious activity.
  • [PROMPT_INJECTION]: The skill processes data from external vulnerability databases, creating a surface for indirect prompt injection. This surface is assessed as safe due to the use of trusted vendor tools and the lack of dangerous capabilities in the skill. 1. Ingestion points: Vulnerability descriptions retrieved via get_endor_vulnerability and get_resource tools in SKILL.md. 2. Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present. 3. Capability inventory: The skill is restricted to informational responses and suggests follow-up commands like /endor-fix, but contains no subprocess calls, file writing, or dynamic code execution. 4. Sanitization: No sanitization of ingested content is explicitly defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 21, 2026, 04:26 AM
Security Audit — agent-trust-hub — endor-explain