product-question
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes Python scripts (
scripts/validate.pyandscripts/test_skill.py) intended for local verification of skill structure and package integrity. These scripts perform local file-system checks and utilize the standardastlibrary for syntax verification.\n- [INDIRECT_PROMPT_INJECTION]:\n - Ingestion points: Codebase files, user-facing labels, route names, and test definitions are processed by the agent during investigation as defined in
references/discovery.md.\n - Boundary markers: Instructions in
SKILL.mdandreferences/discovery.mddirect the agent to separate observed behavior from inference and prioritize strong evidence from runtime code paths.\n - Capability inventory: The skill possesses local file-read capabilities through its execution model and the provided validation scripts.\n
- Sanitization: The 'Share-Ready Answer Standard' enforces a plain-English output format that avoids technical terminology and code dumps, providing a layer of human-readable sanitization for stakeholders.
Audit Metadata