performing-security-audits
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides documentation, report templates, and a basic Python script template for processing files. No obfuscation, data exfiltration, or malicious execution patterns were detected.
- [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as its primary function is to ingest and analyze untrusted external code and infrastructure configurations.
- Ingestion points: External code, configuration files, and system API endpoints provided by the user for auditing (SKILL.md).
- Boundary markers: None identified; instructions do not specify delimiters or warnings for embedded content.
- Capability inventory: The skill has broad capabilities, including shell execution (
Bash(cmd:*)) and file system access (Read,Write,Edit). - Sanitization: No evidence of input validation or sanitization of the data being processed was found in the provided script templates.
Audit Metadata