decomposition-reconstruction
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides a logical framework for system analysis. It does not contain executable code, network operations, or sensitive data access. The instructions focus on structured documentation and analytical thinking.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied system descriptions, which represents an ingestion point for untrusted data.
- Ingestion points: The workflow in
SKILL.mdandresources/template.mdstarts by asking the user to describe the system, problem, and boundaries. - Boundary markers: The instructions explicitly require defining boundaries (scope vs. out-of-scope) and success criteria in Step 1, which acts as a constraint on data processing.
- Capability inventory: The skill lacks high-risk capabilities; it does not request tool permissions (YAML
allowed-toolsis empty) and primarily involves generating a markdown report. - Sanitization: No explicit sanitization or filtering of the user-provided system description is defined.
Audit Metadata