quarterly-zoomout

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data exfiltration attempts were detected. The skill's behavior is consistent with its stated purpose of summarizing internal reports.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources (ops/growth-analyst/.md, ops/curator/.md, and corpus/published/). While this represents a surface for indirect prompt injection if those files contain adversarial instructions, the skill has no high-risk capabilities (such as network access or shell execution) that could be exploited.
  • Ingestion points: Steps 1, 2, and 3 involve globbing and reading multiple markdown files from the project structure.
  • Boundary markers: The skill does not explicitly instruct the agent to ignore instructions embedded within the ingested files.
  • Capability inventory: Analysis of the skill reveals only read-only file access and narrative generation capabilities.
  • Sanitization: No sanitization or validation of the input file content is specified.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 02:36 PM
Security Audit — agent-trust-hub — quarterly-zoomout