evidence-ledger

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The /evidence audit command ingests and processes untrusted data from target artifacts such as markdown files, documents, and proposals to extract and verify factual claims. \n
  • Ingestion points: Target artifacts specified by the user during the /evidence audit procedure (SKILL.md). \n
  • Boundary markers: The skill instructions do not define specific delimiters or warnings to isolate the agent from potentially malicious instructions embedded in the audited documents. \n
  • Capability inventory: The skill has access to tools including bash, write_to_file, replace_file_content, and list_dir (SKILL.md, openai.yaml). \n
  • Sanitization: The procedure for verifying [RAW] evidence does not describe a validation or sanitization step for the commands extracted from the documentation before they are executed. \n- [COMMAND_EXECUTION]: The skill uses the bash tool to verify technical claims tagged with a [RAW] confidence tier by executing shell commands, such as benchmarks and test suites, and capturing their output (SKILL.md, references/claim-verification-taxonomy.md). \n- [EXTERNAL_DOWNLOADS]: The skill fetches content from external sources to verify primary documentation and academic receipts. \n
  • Fetches official documentation from well-known services and organizations, including Next.js (nextjs.org), SQLite (sqlite.org), and Supabase (supabase.com) (SKILL.md, references/academic-citation-protocol.md). \n
  • References and verifies peer-reviewed research papers using DOI links from academic registries like doi.org (SKILL.md, references/academic-citation-protocol.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — evidence-ledger