merge-artifacts

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill operates locally by reading candidate documents and writing a merged result to the docs/threads/ directory. No network exfiltration or unauthorized file access was detected.\n- [NO_CODE]: The skill is composed entirely of natural language instructions; no scripts, binaries, or external dependencies are included.\n- [SAFE]: Evaluation of potential indirect prompt injection: 1. Ingestion points: Candidate Markdown drafts (SKILL.md). 2. Boundary markers: Absent; drafts are read end-to-end. 3. Capability inventory: Filesystem writes to docs/threads/. 4. Sanitization: The instructions require the agent to restate and fold content, which limits the risk of raw instruction execution from draft content.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 01:01 PM
Security Audit — agent-trust-hub — merge-artifacts