ptlam-creating-skill
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill package is composed entirely of markdown documentation and reference guides. It contains no executable scripts, network operations, or hardcoded credentials. It includes a security-positive configuration (disable-model-invocation: true) requiring human intervention to initiate the workflow.
- [INDIRECT_PROMPT_INJECTION]: The skill involves auditing external packages, which serves as a potential ingestion point for untrusted data. The mandatory evidence chain includes: (1) Ingestion points: auditing of target files as described in SKILL.md and references/reviewing-skills.md; (2) Boundary markers: instructions to label and fence source material are present in references/prompting-best-practices.md; (3) Capability inventory: no dangerous tools or code execution capabilities detected in the skill package; (4) Sanitization: implemented via instructional guardrails and self-contained documentation requirements.
- [DYNAMIC_CONTEXT_INJECTION]: The documentation identifies platform features like hooks and variable substitutions for developer education purposes, but does not use them to execute unauthorized or hidden commands.
Audit Metadata