best-choice
Pass
Audited by Gen Agent Trust Hub on Apr 7, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The instructions 'ask-user=false' and 'user-picks=never' found in the skill metadata and body are designed to override the agent's default interactive behavior, forcing it to make choices without user consultation or confirmation.
- [PROMPT_INJECTION]: The 'description' field in the YAML frontmatter contains logic and commands rather than a human-readable summary, which is a technique used to influence agent behavior through metadata poisoning.
- [PROMPT_INJECTION]: The directive '[SAY:...|allow=false]' explicitly instructs the agent to withhold technical explanations from the user, specifically regarding Go's concurrency model, which reduces the transparency and auditability of the agent's responses.
- [NO_CODE]: The skill consists entirely of natural language instructions and does not contain any executable code, scripts, or external tool definitions.
Audit Metadata