community-building

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest untrusted data from users (such as community goals, member descriptions, and project details) which is then used to generate strategic artifacts.\n
  • Ingestion points: User-supplied answers to questions defined in references/INTAKE.md.\n
  • Capability inventory: The agent is instructed in SKILL.md to save generated content as durable markdown files in the content/ directory.\n
  • Boundary markers: The instructions lack explicit boundary markers or directives to ignore instructions that might be embedded within the user-provided data.\n
  • Sanitization: No sanitization or validation mechanisms are implemented to filter malicious content from the user inputs before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 01:07 PM
Security Audit — agent-trust-hub — community-building