content-guidelines

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill is composed entirely of markdown-based style guidelines and terminology references. It does not contain any scripts, binary files, or executable logic.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a data ingestion surface by instructing the agent to review strings from locales/**/*.json files. However, this finding is considered safe because the skill does not possess any tools or capabilities (such as network operations, file writing, or shell execution) that could be leveraged if malicious instructions were present in the locale files.
  • Ingestion points: User-facing product strings in locales/**/*.json.
  • Boundary markers: None explicitly defined in the instructions.
  • Capability inventory: No tool usage, subprocess calls, or network operations are present or enabled.
  • Sanitization: Not applicable as no processing or command execution occurs.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 07:59 PM
Security Audit — agent-trust-hub — content-guidelines