capability-distill
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests untrusted task trajectories and conversation history, which represents an indirect prompt injection surface. \n
- Ingestion points: Processes logs and user-approved local materials as specified in the Operating Contract and Step 0.\n
- Boundary markers: Employs a source_scope mechanism and approved_roots configuration to restrict file system access.\n
- Capability inventory: The distilled logic influences downstream tools (skill-audit, skill-creator), creating a tool chain.\n
- Sanitization: Enforces redaction of PII, tokens, and credentials in Step 0, and uses logic filters (Step 6) to ensure output quality.\n- [SAFE]: The skill incorporates robust defensive measures against data exfiltration and unauthorized access, specifically blocking home directory scanning and unapproved network requests.
Audit Metadata