sem-present
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data which represents a potential attack surface. * Ingestion points: Authoritative Markdown traces specified in SKILL.md. * Boundary markers: Not defined in the instructions. * Capability inventory: Limited to writing view/manifest.json and view/notes.md; no execution or network tools available. * Sanitization: Enforces strict relative path validation, rejecting absolute paths, schemes, and traversal sequences ('..') as defined in references/view-contract.md.
- [SAFE]: The skill instructions explicitly prohibit executing, resuming, or rendering the run data, effectively neutralizing risks of code execution from processed log content.
Audit Metadata