terminology-review
Pass
Audited by Gen Agent Trust Hub on Jul 26, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied text from documents, PR bodies, and messages, which represents a potential attack surface. However, it contains explicit defensive instructions in both
SKILL.mdandreferences/verification-procedure.mdto treat external content as evidence only, ignore any embedded commands or instructions, and preserve user authority boundaries. - [EXTERNAL_DOWNLOADS]: The skill instructs the agent to verify terminology using external sources. These references target well-known and trusted organizations and services, including GitHub, Microsoft, Kubernetes, NIST, and official RFC repositories. The instructions emphasize using these sources for evidence gathering rather than execution.
- [COMMAND_EXECUTION]: The reference files include a
grepcommand example for identifying specific linguistic patterns. This is a standard diagnostic utility used in the context of terminology review and does not involve privilege escalation or unsafe parameter handling.
Audit Metadata