tugboat
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists entirely of instructional text to guide agent behavior. It does not include executable code, external scripts, or network exfiltration patterns.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data regarding their tasks and emotional state (ingestion points: user's account in SKILL.md). It utilizes agent capabilities such as searching, testing, and modifying files (capability inventory: SKILL.md). Boundaries are established through explicit instructions to follow all safety/permission rules and maintain user authority over project goals (boundary markers: SKILL.md). While specific sanitization is not detailed, the restrictive operational stance and requirement for user-led decisions minimize the risk of untrusted input causing harm.
Audit Metadata