discernment-nudge
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is entirely composed of Markdown instructions and a standard Apache 2.0 license. It does not include any executable scripts, binaries, or configuration files that could perform actions on a system.
- [DATA_EXPOSURE]: There are no references to sensitive file paths, environment variables, or hardcoded credentials. The skill operates purely on the text of the conversation.
- [REMOTE_CODE_EXECUTION]: The skill does not include any network operations, external package installations (npm/pip), or remote script downloading patterns.
- [COMMAND_EXECUTION]: No shell commands, subprocess calls, or dynamic command injection patterns were detected in the instructions.
- [PROMPT_INJECTION]: The instructions guide the agent to provide helpful follow-up questions for user reflection. They do not attempt to bypass safety filters, extract system prompts, or override core agent constraints.
- [INDIRECT_PROMPT_INJECTION]: Although the skill processes conversation content to generate follow-up questions, it does not possess any capabilities (like file writing or network access) that could be leveraged by an attacker to cause harm through data ingestion.
Audit Metadata