skill-security-review
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill text includes examples of malicious phrases like "do not tell the user" and "ignore previous/other rules" within an audit checklist. These are listed solely for detection purposes during manual review and are not active instructions for the agent to follow.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing untrusted external files. 1. Ingestion points: external skill files (SKILL.md, scripts, configs). 2. Boundary markers: Absent from the instructional framework. 3. Capability inventory: No tools, file system write permissions, or network execution capabilities are granted to this skill in its configuration. 4. Sanitization: Not specified. While the ingestion surface exists, the lack of tool permissions prevents any theoretical injection from escalating into malicious actions.
Audit Metadata