screening-alert-adjudication-amir-fadavi

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill contains no executable code or scripts. All files consist of markdown instructions, reference documentation, and JSON test cases.
  • [DATA_EXFILTRATION]: The skill is designed to perform targeted external research in Tier 3, which involves sending personal identifiers (such as names and dates of birth) to external search engines to corroborate identity. This behavior is documented as the primary purpose of the skill and is required for its functionality.
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection because it fetches and processes data from external web pages during the research phase.
  • Ingestion points: Web fetching is defined in 'references/tier-3-research.md'.
  • Boundary markers: The instructions do not currently specify the use of delimiters or 'ignore' warnings for the fetched content.
  • Capability inventory: The skill only generates structured report outputs (JSON and narrative) and does not utilize dangerous tools like subprocess execution or file system writes on the untrusted data.
  • Sanitization: There are no explicit sanitization steps mentioned for the fetched text. However, the skill's highly rigid, tier-based rule system and fixed output schema provide significant mitigation against such injections influencing the agent's behavior beyond the intended analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:34 PM
Security Audit — agent-trust-hub — screening-alert-adjudication-amir-fadavi