capability-distill

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests untrusted task trajectories and conversation history, which represents an indirect prompt injection surface. \n
  • Ingestion points: Processes logs and user-approved local materials as specified in the Operating Contract and Step 0.\n
  • Boundary markers: Employs a source_scope mechanism and approved_roots configuration to restrict file system access.\n
  • Capability inventory: The distilled logic influences downstream tools (skill-audit, skill-creator), creating a tool chain.\n
  • Sanitization: Enforces redaction of PII, tokens, and credentials in Step 0, and uses logic filters (Step 6) to ensure output quality.\n- [SAFE]: The skill incorporates robust defensive measures against data exfiltration and unauthorized access, specifically blocking home directory scanning and unapproved network requests.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 12:36 AM
Security Audit — agent-trust-hub — capability-distill