performing-security-audits

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides documentation, report templates, and a basic Python script template for processing files. No obfuscation, data exfiltration, or malicious execution patterns were detected.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as its primary function is to ingest and analyze untrusted external code and infrastructure configurations.
  • Ingestion points: External code, configuration files, and system API endpoints provided by the user for auditing (SKILL.md).
  • Boundary markers: None identified; instructions do not specify delimiters or warnings for embedded content.
  • Capability inventory: The skill has broad capabilities, including shell execution (Bash(cmd:*)) and file system access (Read, Write, Edit).
  • Sanitization: No evidence of input validation or sanitization of the data being processed was found in the provided script templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 11:31 AM
Security Audit — agent-trust-hub — performing-security-audits