persona-auditor
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: No malicious patterns or security risks detected. The skill is purely instructional and defines a persona for conducting technical audits.
- [NO_CODE]: The skill does not include any executable scripts, binaries, or configuration that triggers automatic code execution.
- [SAFE]: Indirect Prompt Injection Surface Analysis:
- Ingestion points: The agent is instructed to read source files and process output from commands found in the workspace's AGENTS.md.
- Boundary markers: The instructions do not explicitly require the use of delimiters when quoting source code or command output in the audit report.
- Capability inventory: The agent is authorized to read files, perform searches (grep), and execute pre-defined commands from the local workspace configuration.
- Sanitization: There are no instructions for sanitizing or escaping content read from the workspace before inclusion in reports.
Audit Metadata