religion

Pass

Audited by Gen Agent Trust Hub on Jun 27, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill does not contain any malicious code, external dependencies, or unauthorized access patterns. It functions as a set of analytical guidelines for the agent.
  • [NO_CODE]: The skill is composed entirely of markdown-based instructions and metadata, with no accompanying scripts or binary executables.
  • [METADATA_POISONING]: The skill's frontmatter lists the author as 'Wizards of the Ghosts', which differs from the provided author context 'Hmbown'. This is a metadata inconsistency but presents no direct security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user descriptions of organizational cultures, creating an indirect prompt injection surface. 1. Ingestion points: User-provided cultural data (SKILL.md, Procedure step 2). 2. Boundary markers: Procedure step 1 instructs the agent to restate 'no-touch boundaries'. 3. Capability inventory: No tools or technical capabilities are requested or used. 4. Sanitization: No explicit validation or filtering logic is defined for the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 27, 2026, 07:47 PM
Security Audit — agent-trust-hub — religion