ai-readiness-assessment

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external, potentially untrusted data sources including business documentation and codebases as described in its methodology. \n
  • Ingestion points: Document review and codebase analysis are explicitly mentioned as information-gathering channels in references/methodology.md. \n
  • Boundary markers: The instructions lack delimiters or explicit 'ignore embedded instructions' warnings for when the agent processes these external materials. \n
  • Capability inventory: The skill has access to sensitive tools including Bash, Write, Read, and WebFetch as defined in the SKILL.md frontmatter. \n
  • Sanitization: No evidence of input validation, escaping, or filtering of external content is present in the provided instructions or methodology.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — ai-readiness-assessment