skills/ericrisco/rsc-harness/bro/Gen Agent Trust Hub

bro

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided text or previous responses for rewriting, which creates a surface for potential indirect prompt injection attacks.
  • Ingestion points: The skill ingests data from the user's pasted text or the assistant's last message as defined in the 'The contract' section of SKILL.md.
  • Boundary markers: The skill explicitly instructs the agent to treat rewritten text as an 'artifact' and keep harness commentary outside it, providing a logical boundary for outputs.
  • Capability inventory: The skill is strictly limited to text rewriting and drafting. It does not invoke system commands, network requests, or file writes.
  • Sanitization: No explicit data sanitization or escaping is performed on the ingested text; the skill relies on the model's ability to follow the instruction to 'preserve the payload' (facts, links, numbers) while ignoring instructions that might be embedded in the source text.
  • [SAFE]: No malicious patterns such as obfuscation, credential harvesting, privilege escalation, or remote code execution were detected. The skill uses standard markdown and YAML configurations to define its behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:10 PM
Security Audit — agent-trust-hub — bro