skills/fusengine/agents/challenge/Gen Agent Trust Hub

challenge

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data (claims and evidence) for verification purposes. Ingestion points: The 'Intake' step in SKILL.md receives claims verbatim. Boundary markers: The agent is instructed to discard narrative and leaked reasoning before processing. Capability inventory: The skill has read-only access to file system tools (Read/Grep/Glob) and vendor-specific browser tools. Sanitization: The protocol mandates discarding narrative components to focus solely on the claim and evidence.
  • [PRIVILEGE_ESCALATION]: The skill identifies sensitive operations such as 'rm', 'deploy', and 'push' as trigger conditions for its verification protocol. Analysis confirms these are monitored events used to initiate the challenge process and are not commands executed by the skill, which is explicitly restricted to read-only, consultative actions.
  • [UNVERIFIABLE_DEPENDENCIES]: The protocol utilizes Exa and fuse-browser (vendor resources from fusengine) for information gathering. These tools are used to fetch external documentation and source code to verify the accuracy of claims during the investigation rounds.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 04:06 PM
Security Audit — agent-trust-hub — challenge