finding-generator
Pass
Audited by Gen Agent Trust Hub on Jul 27, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill does not contain any evidence of credential theft, data exfiltration, or unauthorized command execution. No external network requests or script executions were identified.
- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it ingests and structures user-supplied audit information.
- Ingestion points: The skill processes user-provided finding details (Condition, Criteria, Cause, Effect) to generate structured audit reports.
- Boundary markers: No specific delimiters or instructions to ignore embedded commands are present in the skill definition.
- Capability inventory: The skill is authorized to use Read and Write tools.
- Sanitization: The instructions do not define any validation, escaping, or filtering for the input data before it is formatted into the output.
Audit Metadata