zephyr-routing

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its handling of untrusted data from documents.
  • Ingestion points: The skill processes arbitrary source documents to identify and route "Zephyr entries" based on H2 headers and keyword keys (SKILL.md).
  • Boundary markers: While it uses H2 headings as delimiters, it lacks specific instructions to the agent to ignore or escape any instructions that might be embedded within the content of those entries.
  • Capability inventory: The agent is authorized to perform file creation (Create Missing Targets), file deletion (Delete Empty Source), and version control operations (Commit).
  • Sanitization: The instructions describe weight normalization for deduplication but do not provide for the sanitization of entry body content.
  • [COMMAND_EXECUTION]: The skill instructs the agent to perform multiple file system and version control operations.
  • Evidence: The skill explicitly directs the agent to create new files for missing targets, delete source files after routing in move mode, and perform separate Git commits for each modified or deleted file.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 08:10 PM
Security Audit — agent-trust-hub — zephyr-routing