env-capability-discovery

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill defines an environment discovery protocol that ingests metadata from other installed skills to determine workflow enhancements.
  • Ingestion points: The skill reads names and descriptions from the system prompt's available-items listing or the platform's skill-listing tool (referenced in SKILL.md).
  • Boundary markers: There are no instructions to use delimiters or markers to prevent the agent from following instructions embedded within the scanned skill descriptions.
  • Capability inventory: The skill allows for the dynamic invocation of discovered skills matching specific functional keywords (referenced in SKILL.md).
  • Sanitization: The discovery process uses keyword matching but does not specify validation or sanitization of the targeted skill's content before invocation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 05:00 PM
Security Audit — agent-trust-hub — env-capability-discovery