s4h-resource-waste-audit
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of markdown instructions and does not include any scripts, commands, or binary files. No malicious patterns were detected.
- [PROMPT_INJECTION]: The skill accepts user-provided workflow descriptions as input (Category 8: Indirect Prompt Injection surface).
- Ingestion points: User input provided in 'Step 1: Map the Workflow' and subsequent feedback loops.
- Boundary markers: Absent; there are no explicit delimiters or instructions to ignore embedded commands in user data.
- Capability inventory: Uses the
AskUserQuestiontool for interaction. No file system, shell execution, or network capabilities are present in the skill definition. - Sanitization: Absent; the skill does not specify any validation or filtering of user-provided content. Since the skill has no dangerous capabilities, this surface poses no significant risk.
Audit Metadata