sherpa
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of natural language instructions designed to help an agent manage complex tasks through decomposition and progress tracking. It does not perform any sensitive operations.
- [NO_CODE]: No executable scripts, binaries, or configuration files are included. The skill functions solely as a behavioral guide for the AI agent.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external task descriptions provided by the user. While this represents an ingestion point for untrusted data, the skill lacks the capabilities (such as tool usage, file system access, or network connectivity) to act upon malicious instructions if they were present in the input.
- Ingestion points: User-provided task descriptions in the chat context.
- Boundary markers: None present.
- Capability inventory: No tools or command execution capabilities are defined or requested.
- Sanitization: None present.
Audit Metadata