skills/iskron-ai/skills/assembly/Gen Agent Trust Hub

assembly

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and interpret complex graph data (referred to as vimarshas, kriyas, and bianhua) which may originate from external or user-provided sources. While the skill instructs the agent to consult the user for high-level decisions, it lacks explicit boundary markers for untrusted data processed through its tools.
  • Ingestion points: Data is retrieved via iskron_orient and iskron_search (SKILL.md).
  • Boundary markers: None specified for the content returned by graph orientation tools.
  • Capability inventory: The skill utilizes write-capable tools such as iskron_add_bianhua and iskron_add_kriya (SKILL.md) to modify the workspace.
  • Sanitization: No explicit sanitization or instruction to ignore embedded directives in the graph data is provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 01:34 PM
Security Audit — agent-trust-hub — assembly