quality-gates

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves reading project-specific files, such as hook outputs, event registries, and the .jimmy/ directory, to verify completion evidence. This identifies an ingestion surface where untrusted content in files could influence the agent; however, the skill's purpose is specifically to provide a framework for evidence-based verification, and no high-risk capabilities are exposed.
  • Ingestion points: Event registries, hook outputs, and files under the .jimmy/ directory.
  • Boundary markers: Not explicitly defined in the provided instructions.
  • Capability inventory: No scripts or tools are provided for execution.
  • Sanitization: Not specified.
  • [SAFE]: No other malicious patterns, such as obfuscation, command execution, or unauthorized network operations, were detected. The reference to the public GitHub repository github.com/xoai/sage is informational and for documentation only.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 12:13 PM
Security Audit — agent-trust-hub — quality-gates