decomposition-reconstruction

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a logical framework for system analysis. It does not contain executable code, network operations, or sensitive data access. The instructions focus on structured documentation and analytical thinking.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied system descriptions, which represents an ingestion point for untrusted data.
  • Ingestion points: The workflow in SKILL.md and resources/template.md starts by asking the user to describe the system, problem, and boundaries.
  • Boundary markers: The instructions explicitly require defining boundaries (scope vs. out-of-scope) and success criteria in Step 1, which acts as a constraint on data processing.
  • Capability inventory: The skill lacks high-risk capabilities; it does not request tool permissions (YAML allowed-tools is empty) and primarily involves generating a markdown report.
  • Sanitization: No explicit sanitization or filtering of the user-provided system description is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 06:00 AM
Security Audit — agent-trust-hub — decomposition-reconstruction