prose-polish

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is comprised entirely of Markdown files providing instructions and reference patterns for text evaluation. No executable scripts (e.g., Python, JavaScript, Shell) or binary files are included.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: No hardcoded credentials, API keys, or sensitive file paths (e.g., SSH keys, AWS configs) were detected. The skill does not perform any network operations to transmit data externally.
  • [PROMPT_INJECTION]: Instructions such as the 'Fidelity Firewall' and 'Anti-Cliché' patterns are used for task-specific quality control and do not attempt to bypass the AI agent's core safety protocols or override behavioral constraints.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided drafts for analysis, but it lacks dangerous capabilities like shell command execution or network access, which effectively mitigates the impact of potential indirect injection attacks.
  • [OBFUSCATION]: No obfuscation techniques, including Base64-encoded strings, zero-width characters, or hidden URLs, were identified in the source files.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not use dynamic shell execution patterns (e.g., !command syntax) within its instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 12:44 PM
Security Audit — agent-trust-hub — prose-polish