route-next-steps
Pass
Audited by Gen Agent Trust Hub on Jul 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes external profile data which acts as an ingestion point for indirect instructions. \n
- Ingestion points: Data from GitHub and LinkedIn profiles (referenced in SKILL.md). \n
- Boundary markers: Includes instructions to confirm the plan with the user and explicit prohibitions against inventing external URLs. \n
- Capability inventory: The skill is restricted to text generation for action plans and drafts; no system execution or network tools are invoked. \n
- Sanitization: Relies on LLM-level safety and explicit negative constraints in the instructions.\n- [SAFE]: No obfuscation, data exfiltration patterns, or unauthorized credential access were found in the file.
Audit Metadata