shortcut-defense
Pass
Audited by Gen Agent Trust Hub on Oct 7, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of prompt injection or instructions to bypass safety guidelines was found. The content focuses on educational frameworks for decision-making and cognitive defense.
- [DATA_EXFILTRATION]: No network operations, sensitive file path access, or credential harvesting patterns were detected. The skill operates entirely within the reasoning context of the agent.
- [REMOTE_CODE_EXECUTION]: No remote scripts, package installations, or external code fetches are present. All references are to local internal documentation.
- [OBFUSCATION]: The content is written in clear Markdown and JSON. No Base64, zero-width characters, homoglyphs, or other obfuscation techniques were identified.
- [DYNAMIC_CONTEXT_INJECTION]: No use of dynamic command execution patterns (e.g., shell command placeholders) was found in the documentation.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided scenarios, it lacks high-risk capabilities such as file system writing or network requests that would make it a significant target for indirect injection attacks. The skill defines clear boundaries for when the framework should not be applied.
Audit Metadata