skill-injection-defense

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill acts as a security auditor for AI workflows. It contains an inherent attack surface for indirect prompt injection because it processes untrusted inputs (Ingestion points: skill files, prompts, and scripts in SKILL.md), but this is mitigated by robust safety instructions (Boundary markers: explicit requirement to treat data as untrusted and ignore embedded commands in SKILL.md). The skill defines a review procedure without requiring external tools or executable code (Capability inventory), and relies on behavioral guidelines for safety (Sanitization).
  • [SAFE]: No other security concerns such as credential exposure or malicious network activity were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:33 PM
Security Audit — agent-trust-hub — skill-injection-defense