lyra

Pass

Audited by Gen Agent Trust Hub on Apr 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is implemented as a set of instructional markdown files with no executable scripts or external dependencies. It follows secure patterns for role-based prompt engineering and interactive context gathering.- [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided prompts via the $ARGUMENTS variable, which constitutes a potential injection surface. However, the risk is managed by the skill's specific focus on text transformation and the use of templated search queries that do not execute arbitrary user instructions. 1. Ingestion points: User prompts are ingested through the $ARGUMENTS variable in SKILL.md. 2. Boundary markers: The skill does not employ explicit delimiters to isolate user input from its internal deconstruction and diagnosis logic. 3. Capability inventory: The skill has access to the Read, Glob, WebSearch, and AskUserQuestion tools. 4. Sanitization: No sanitization is performed on user-supplied prompt text.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 26, 2026, 10:55 AM
Security Audit — agent-trust-hub — lyra