quality-gates
Pass
Audited by Gen Agent Trust Hub on Sep 16, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's workflow involves reading project-specific files, such as hook outputs, event registries, and the .jimmy/ directory, to verify completion evidence. This identifies an ingestion surface where untrusted content in files could influence the agent; however, the skill's purpose is specifically to provide a framework for evidence-based verification, and no high-risk capabilities are exposed.
- Ingestion points: Event registries, hook outputs, and files under the .jimmy/ directory.
- Boundary markers: Not explicitly defined in the provided instructions.
- Capability inventory: No scripts or tools are provided for execution.
- Sanitization: Not specified.
- [SAFE]: No other malicious patterns, such as obfuscation, command execution, or unauthorized network operations, were detected. The reference to the public GitHub repository github.com/xoai/sage is informational and for documentation only.
Audit Metadata