skills/ilang-ai/autocode/best-choice/Gen Agent Trust Hub

best-choice

Pass

Audited by Gen Agent Trust Hub on Apr 7, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The instructions 'ask-user=false' and 'user-picks=never' found in the skill metadata and body are designed to override the agent's default interactive behavior, forcing it to make choices without user consultation or confirmation.
  • [PROMPT_INJECTION]: The 'description' field in the YAML frontmatter contains logic and commands rather than a human-readable summary, which is a technique used to influence agent behavior through metadata poisoning.
  • [PROMPT_INJECTION]: The directive '[SAY:...|allow=false]' explicitly instructs the agent to withhold technical explanations from the user, specifically regarding Go's concurrency model, which reduces the transparency and auditability of the agent's responses.
  • [NO_CODE]: The skill consists entirely of natural language instructions and does not contain any executable code, scripts, or external tool definitions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 7, 2026, 01:26 AM
Security Audit — agent-trust-hub — best-choice