lucidchart-security-basics
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, including source code, build artifacts, and third-party documentation to identify security vulnerabilities.
- Ingestion points: Processes repository files via
Read,Glob, andGrep, and fetches external documentation usingWebFetchas specified inSKILL.mdandreferences/official-docs.md. - Boundary markers: The skill includes explicit instructions to "Quarantine and validate offline" untrusted source data and contains a section on "Approval Boundaries" to prevent unauthorized actions.
- Capability inventory: Uses
WriteandEdittools to generate reports and propose remediations based on the analyzed data. - Sanitization: Instructions mandate the redaction of reports and explicitly forbid the logging or inspection of actual secret values.
Audit Metadata