grounding

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill includes specific defensive instructions to mitigate indirect prompt injection from course content. Evidence chain: (1) Ingestion points: search_dometrain, search_code, and get_lesson tools in SKILL.md. (2) Boundary markers: Explicit 'untrusted reference data' warnings are present in the 'Purpose' section. (3) Capability inventory: Tool access is limited to the defined MCP functions, with no dangerous shell or file-write capabilities. (4) Sanitization: The skill uses instructional constraints to ensure the agent ignores any directives embedded in returned lesson text.\n- [EXTERNAL_DOWNLOADS]: The skill references official resources from dometrain.com and its public repository github.com/Dometrain/mcp. These are well-known services and the downloads/references are appropriate for the skill's purpose.\n- [COMMAND_EXECUTION]: No dangerous shell commands, scripts, or privilege escalation patterns were detected. The skill logic is confined to standard metadata and instructional guidance.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 07:56 PM
Security Audit — agent-trust-hub — grounding