evidence-ledger
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
/evidence auditcommand ingests and processes untrusted data from target artifacts such as markdown files, documents, and proposals to extract and verify factual claims. \n - Ingestion points: Target artifacts specified by the user during the
/evidence auditprocedure (SKILL.md). \n - Boundary markers: The skill instructions do not define specific delimiters or warnings to isolate the agent from potentially malicious instructions embedded in the audited documents. \n
- Capability inventory: The skill has access to tools including
bash,write_to_file,replace_file_content, andlist_dir(SKILL.md, openai.yaml). \n - Sanitization: The procedure for verifying
[RAW]evidence does not describe a validation or sanitization step for the commands extracted from the documentation before they are executed. \n- [COMMAND_EXECUTION]: The skill uses thebashtool to verify technical claims tagged with a[RAW]confidence tier by executing shell commands, such as benchmarks and test suites, and capturing their output (SKILL.md, references/claim-verification-taxonomy.md). \n- [EXTERNAL_DOWNLOADS]: The skill fetches content from external sources to verify primary documentation and academic receipts. \n - Fetches official documentation from well-known services and organizations, including Next.js (nextjs.org), SQLite (sqlite.org), and Supabase (supabase.com) (SKILL.md, references/academic-citation-protocol.md). \n
- References and verifies peer-reviewed research papers using DOI links from academic registries like doi.org (SKILL.md, references/academic-citation-protocol.md).
Audit Metadata