s4h-constraint-scope-reduction
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is primarily a set of text-based instructions for analyzing project scope. No malicious patterns such as obfuscation, remote code execution, privilege escalation, or credential theft were found.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of user-provided project requirements (Step 1 and Step 2 in SKILL.md). Boundary markers are absent. The capability inventory is limited to text generation and the AskUserQuestion tool, with no file system or network access. Sanitization of user input is absent, but the risk is negligible as there are no executable capabilities to exploit.
Audit Metadata