lucidchart-security-basics

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, including source code, build artifacts, and third-party documentation to identify security vulnerabilities.
  • Ingestion points: Processes repository files via Read, Glob, and Grep, and fetches external documentation using WebFetch as specified in SKILL.md and references/official-docs.md.
  • Boundary markers: The skill includes explicit instructions to "Quarantine and validate offline" untrusted source data and contains a section on "Approval Boundaries" to prevent unauthorized actions.
  • Capability inventory: Uses Write and Edit tools to generate reports and propose remediations based on the analyzed data.
  • Sanitization: Instructions mandate the redaction of reports and explicitly forbid the logging or inspection of actual secret values.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:10 AM
Security Audit — agent-trust-hub — lucidchart-security-basics