skills/iuliandita/skills/jekyll-hyde/Gen Agent Trust Hub

jekyll-hyde

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a structured framework for decision analysis using dual personas. The adversarial Hyde mode is explicitly constrained to be diagnostic and is prohibited from making final calls or bypassing safety boundaries, ensuring it remains a strategy tool rather than a jailbreak vector.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided decisions as primary input, which creates a theoretical attack surface for indirect prompt injection. (1) Ingestion points: User input via the argument hint defined in SKILL.md. (2) Boundary markers: No specific delimiters or markers are defined in the skill instructions to isolate user-provided data from the agent's instructions. (3) Capability inventory: The skill is limited to generating text advice and writing markdown deliverable files to a scoped local directory (docs/local/deliverables/jekyll-hyde/) and lacks network access or arbitrary command execution capabilities. (4) Sanitization: No explicit sanitization of the user-provided decision context is performed, though the risk is evaluated as safe given the limited capability tier.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 08:19 AM
Security Audit — agent-trust-hub — jekyll-hyde