finding-generator

Pass

Audited by Gen Agent Trust Hub on Jul 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill does not contain any evidence of credential theft, data exfiltration, or unauthorized command execution. No external network requests or script executions were identified.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it ingests and structures user-supplied audit information.
  • Ingestion points: The skill processes user-provided finding details (Condition, Criteria, Cause, Effect) to generate structured audit reports.
  • Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the skill definition.
  • Capability inventory: The skill is authorized to use Read and Write tools.
  • Sanitization: The instructions do not define any validation, escaping, or filtering for the input data before it is formatted into the output.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 27, 2026, 12:26 PM
Security Audit — agent-trust-hub — finding-generator