sota-confidential-computing

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted system documentation and configuration data during its analysis modes, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: System design documents and architecture claims processed in BUILD and AUDIT modes (SKILL.md).\n
  • Boundary markers: Absent; inputs are not explicitly wrapped in delimiters or accompanied by warnings to ignore embedded instructions.\n
  • Capability inventory: Limited to technical analysis and report generation; no shell execution, file-writing, or network capabilities are exposed through the skill instructions.\n
  • Sanitization: Absent; external content is analyzed as-is without filtering.\n
  • Context: The skill is assessed as safe because it lacks the exploitable capabilities necessary for a prompt injection to achieve high-impact malicious actions, and the agent is instructed to follow strict, technically rigorous rules.\n- [EXTERNAL_DOWNLOADS]: The documentation references official resources from established technology providers, including AMD, Intel, NVIDIA, AWS, Microsoft, and Google, as well as the Confidential Computing Consortium. These references are used appropriately for the verification of hardware and security standards and do not involve the execution of untrusted remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 10:17 PM
Security Audit — agent-trust-hub — sota-confidential-computing