detect-magic

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or suspicious code were detected. The skill is purely instructional and guides the agent through a logical repository analysis process.
  • [INDIRECT_PROMPT_INJECTION]: The skill functions by scanning untrusted project files, creating an attack surface for indirect prompt injection.
  • Ingestion points: Files within a repository or system being scanned (SKILL.md).
  • Boundary markers: The procedure requires the agent to restate "no-touch boundaries" before beginning the scan, providing a safety checkpoint.
  • Capability inventory: The skill utilizes the agent's native environment tools (such as file reading and searching) rather than providing custom executables.
  • Sanitization: No specific content filtering or sanitization is mentioned, though the instructions explicitly warn against executing discovered hooks or automations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 07:47 PM
Security Audit — agent-trust-hub — detect-magic