offer
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill operates within a controlled local environment and adheres to a strict verification protocol for all data writes. No evidence of malicious intent or unauthorized access was found.
- [COMMAND_EXECUTION]: The skill is configured to run the local script scripts/graph-audit to verify file integrity. This is an internal tool within the vendor's repository used for structural validation and does not involve network activity or untrusted external code.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied pricing queries and vault data (Ingestion points: SKILL.md, references/CONVENTIONS-core.md). It uses a 'durable claim admission gate' as a boundary marker to prevent unverified data from becoming facts. Capabilities are limited to local file updates and integrity auditing, with sanitization performed by requiring direct quoted receipts for all durable claims.
Audit Metadata