staged-review-flow
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFENO_CODECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is composed of markdown instructions and does not include any executable scripts or binaries.
- [COMMAND_EXECUTION]: The skill instructs the agent to display an installation command (
npx skills add FuDesign2008/open-skills) if required dependencies are missing. This points to the vendor's own repository for skill management. - [INDIRECT_PROMPT_INJECTION]: The skill processes verification reports and completion evidence. 1. Ingestion points: Verification reports and results are ingested in the review stage within the SKILL.md flow. 2. Boundary markers: No explicit boundary markers or delimiters are defined for the ingested data. 3. Capability inventory: The skill does not possess file system, network, or subprocess capabilities in its current definitions. 4. Sanitization: The 'verification-report honesty' rule requires agents to disclose actual execution states rather than reporting inferred results, providing a procedural filter for external data.
Audit Metadata