skills/iskron-ai/skills/entry/Gen Agent Trust Hub

entry

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected during the analysis of the skill. The instructions and referenced tool patterns align with the stated purpose of methodology orientation and graph data interaction.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill uses specialized 'iskron_*' tools to interact with a knowledge graph. There is no evidence of hardcoded credentials, access to sensitive local file paths (such as .ssh or .aws), or network exfiltration to untrusted domains. References to graph addresses (e.g., '@owner/slug') are standard identifiers for the system.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns, such as piped shell commands from external URLs, were identified. The skill references other internal skills (e.g., 'establish-mcp', 'standing') for environment setup, which is expected for modular agent functionality.
  • [PROMPT_INJECTION]: The instructions are highly prescriptive regarding the 'Iskron' methodology but do not contain attempts to bypass safety filters, extract system prompts, or override the agent's core safety guidelines.
  • [OBFUSCATION]: The content uses standard Russian and English terminology. No multi-layer Base64, zero-width characters, homoglyph attacks, or hidden text patterns were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from an external graph database via 'iskron_search' and 'iskron_look'. While this provides an ingestion surface for potential indirect injections, the instructions emphasize logical verification ('check against reality') and structured processing, which serves as a functional guardrail. The risk level is consistent with standard data-processing skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 01:34 PM
Security Audit — agent-trust-hub — entry