skills/hani-q/qstack/qstack-unyap/Gen Agent Trust Hub

qstack-unyap

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of instructions designed to bypass safety filters or override system prompts was found. The skill's instructions are strictly limited to text transformation and simplification tasks.- [DATA_EXFILTRATION]: No network activity, hardcoded credentials, or access to sensitive file paths were detected. The skill explicitly directs the agent to remove file paths and technical details from its output, which aligns with data minimization practices.- [REMOTE_CODE_EXECUTION]: The skill consists entirely of natural language instructions and configuration metadata. It does not download external scripts, install packages, or execute shell commands.- [INDIRECT_PROMPT_INJECTION]: The skill processes the agent's previous response as input. While this represents a theoretical ingestion surface for untrusted data, the instructions to simplify, shorten, and remove jargon act as functional constraints that mitigate the risk of the agent following embedded instructions in the processed text.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 11:57 AM
Security Audit — agent-trust-hub — qstack-unyap