show-me
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of instructions for formatting visualizations like Mermaid diagrams and file trees. No malicious code, obfuscation, or unauthorized access patterns were found.
- [INDIRECT_PROMPT_INJECTION]: The skill generates artifacts based on conversation context, which is a surface for indirect prompt injection. The risk is considered safe as the agent primarily generates descriptive content and no high-risk capabilities are exposed.
- Ingestion points: Conversation topic and history (SKILL.md).
- Boundary markers: None defined.
- Capability inventory:
Bash(open ...)command usage for viewing generated files. - Sanitization: None explicitly specified.
Audit Metadata