s4h-resource-waste-audit

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed entirely of markdown instructions and does not include any scripts, commands, or binary files. No malicious patterns were detected.
  • [PROMPT_INJECTION]: The skill accepts user-provided workflow descriptions as input (Category 8: Indirect Prompt Injection surface).
  • Ingestion points: User input provided in 'Step 1: Map the Workflow' and subsequent feedback loops.
  • Boundary markers: Absent; there are no explicit delimiters or instructions to ignore embedded commands in user data.
  • Capability inventory: Uses the AskUserQuestion tool for interaction. No file system, shell execution, or network capabilities are present in the skill definition.
  • Sanitization: Absent; the skill does not specify any validation or filtering of user-provided content. Since the skill has no dangerous capabilities, this surface poses no significant risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 11:43 PM
Security Audit — agent-trust-hub — s4h-resource-waste-audit