to-questionnaire

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted user input and interpolate it directly into a local file and its filename.
  • Ingestion points: User input regarding the recipient's role, expertise, and specific requirements is collected through conversational exchanges defined in SKILL.md.
  • Boundary markers: The instructions do not define delimiters or specific system instructions to ignore potential commands embedded within the user's descriptive responses.
  • Capability inventory: The skill possesses the capability to write files to the local file system (to-questionnaire-<slug>.md).
  • Sanitization: There are no explicit instructions or regex patterns provided to sanitize the 'slug' (used in the filename) or the questionnaire content, potentially allowing for path traversal or content injection if not handled by the platform's underlying file-writing tool.
  • [NO_CODE]: The skill consists entirely of instructional Markdown and YAML configuration. It does not include or execute any scripts, binaries, or external code dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 05:30 PM
Security Audit — agent-trust-hub — to-questionnaire