skill-security-review

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEPROMPT_INJECTIONINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill text includes examples of malicious phrases like "do not tell the user" and "ignore previous/other rules" within an audit checklist. These are listed solely for detection purposes during manual review and are not active instructions for the agent to follow.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for processing untrusted external files. 1. Ingestion points: external skill files (SKILL.md, scripts, configs). 2. Boundary markers: Absent from the instructional framework. 3. Capability inventory: No tools, file system write permissions, or network execution capabilities are granted to this skill in its configuration. 4. Sanitization: Not specified. While the ingestion surface exists, the lack of tool permissions prevents any theoretical injection from escalating into malicious actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 10:41 AM
Security Audit — agent-trust-hub — skill-security-review