dissect-and-interview

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: Analysis of indirect prompt injection surface:
  • Ingestion points: The skill explores local codebase files (SKILL.md) to extract evidence for generating interview questions.
  • Boundary markers: Absent; there are no explicit instructions to the model to ignore instructions embedded within the analyzed code.
  • Capability inventory: The skill is limited to reading files and generating text; it does not perform network operations, file system writes, or command execution.
  • Sanitization: Absent; the skill does not mention escaping or validating the content of the source code it processes.
  • Risk assessment: While the skill processes untrusted external data (the codebase), the risk is limited to influencing the agent's behavior during the interview session. The absence of dangerous tools prevents this from being a high-severity threat.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 04:50 PM
Security Audit — agent-trust-hub — dissect-and-interview