mindtickle-debug-bundle

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements privacy-by-design principles, requiring the agent to use redaction policies, PII aliasing, and secret scanning before outputting any data.
  • [SAFE]: External references are limited to official Mindtickle documentation and legal pages.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted local data such as logs and configuration files (ingestion points in SKILL.md), which represents an indirect prompt injection surface. The skill includes mitigation through boundary markers (explicit allowlists and denylists) and sanitization (redaction and secret scanning) before performing actions like writing to a manifest or using WebFetch. The agent's capabilities include Read, Glob, Grep, WebFetch, Write, and Edit.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 06:59 AM
Security Audit — agent-trust-hub — mindtickle-debug-bundle