deslop
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's primary function is stylistic text processing and editing based on predefined diagnostic patterns. No malicious instructions or hidden behaviors were found.
- [COMMAND_EXECUTION]: The skill utilizes a local Perl script (
slopscan.pl) and a Bash script (selftest.sh). These scripts are used for mechanical scanning and regression testing respectively. They perform only local file reading and regex-based text analysis without any network activity, sensitive data access, or privilege escalation. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted prose inputs, creating a surface for indirect prompt injection. However, it incorporates several mitigation strategies: a formal 'Preservation contract' that instructs the agent to protect code and metadata, and a mechanical scanner that uses a masking heuristic to ignore content inside code blocks and quotes. The risk is assessed as safe.
- [EXTERNAL_DOWNLOADS]: The skill does not perform any external downloads. All scripts and reference materials are included locally within the skill repository.
Audit Metadata