attribute-performance

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external web sources which could contain malicious instructions.
  • Ingestion points: Fetches Substack post content and social mentions via the WebFetch tool in SKILL.md.
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present in the workflow.
  • Capability inventory: No dangerous system capabilities such as shell execution, file system modification, or credential access were identified.
  • Sanitization: No validation or sanitization of the fetched external content is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:36 PM
Security Audit — agent-trust-hub — attribute-performance