swebok-models-and-methods

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and evaluate software models provided by users, which could potentially contain embedded instructions intended to override the agent's behavior.
  • Ingestion points: The agent is directed to process user-provided system descriptions, architectural models, and formal specifications as described in SKILL.md.
  • Boundary markers: While the skill defines a structured output format for the agent, it does not provide explicit markers or instructions to isolate user-provided data from the agent's core instructions.
  • Capability inventory: The skill definition does not include any scripts, tool calls, network requests, or file system modifications.
  • Sanitization: There are no instructions for the agent to sanitize, escape, or validate the content of the models it processes.
  • [NO_CODE]: The skill is composed entirely of markdown instructions and YAML metadata. It does not ship with any scripts, binaries, or automated shell commands, which significantly limits its direct risk profile.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 03:56 PM
Security Audit — agent-trust-hub — swebok-models-and-methods