iii-queue-processing

Pass

Audited by Gen Agent Trust Hub on Mar 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The documentation describes a consumer function pattern that processes external job payloads, which represents a surface for indirect prompt injection. * Ingestion points: Job payloads are ingested by registered consumer functions as described in SKILL.md. * Boundary markers: No explicit delimiters or instructions to ignore embedded commands are included in the documentation. * Capability inventory: The pattern includes state modification (state::set) and subsequent job dispatching (TriggerAction.Enqueue) as noted in the architecture and patterns sections. * Sanitization: No sanitization or validation steps for incoming payload data are defined in the reference pattern.
  • [SAFE]: No obfuscation, multi-layer encoding, or hidden content was found in the analysis of the skill documentation.
  • [SAFE]: The skill is correctly attributed to the vendor iii-hq and references standard configuration files and local implementation examples within the vendor's expected namespace.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 31, 2026, 06:34 PM