create-service-object
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No prompt injection, DAN, or behavioral override patterns were detected. The instructions follow standard technical guidance.
- [SAFE]: No hardcoded credentials, sensitive file path access, or unauthorized network operations were found. The code examples use generic placeholders.
- [SAFE]: No obfuscation techniques, such as Base64 encoding of executable content, zero-width characters, or homoglyph attacks, were identified.
- [SAFE]: The skill does not perform external package installations or execute remote code (e.g., via curl | bash).
- [SAFE]: No privilege escalation commands (like sudo) or persistence mechanisms (like cron jobs or shell profile modifications) were found.
- [SAFE]: No dynamic execution patterns, such as eval() or unsafe deserialization, were present in the Ruby templates.
- [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: Ruby
paramshashes defined in service skeletons acrossSKILL.mdandassets/template.rb. - Boundary markers: Not applicable as the skill provides code templates rather than processing live data streams.
- Capability inventory: Includes database transaction wrapping and application logging in
assets/service_skeleton.md. - Sanitization: The skill explicitly requires SQL sanitization for all dynamic queries in the constraints section of
SKILL.md.
Audit Metadata