using-deconstruct-toolkit

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains purely instructional content for routing users based on the type of artifact they provide. No bypass patterns or instructions to ignore safety guidelines were found.
  • [DATA_EXFILTRATION]: No network operations, sensitive file path access, or credential harvesting patterns are present in the skill files.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts or unverified dependencies.
  • [COMMAND_EXECUTION]: No shell commands, subprocess spawning, or dynamic context injection (!command) were identified in the logic.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests user artifacts to determine routing, it explicitly instructs the agent not to perform analysis in this step, effectively limiting the attack surface. It includes boundary checks and filters (length, information-only) before dispatching to sibling skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 05:05 PM
Security Audit — agent-trust-hub — using-deconstruct-toolkit