knowledge-gap-map
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is comprised entirely of natural language instructions for the agent to follow during a conversation. It does not include any scripts, commands, or system calls that could pose a security threat.
- [NO_CODE]: Analysis confirms the absence of Python or Node.js packages, build scripts, or remote code execution patterns.
- [INDIRECT_PROMPT_INJECTION]: Surface identified: (1) Ingestion points: The skill processes user-supplied inputs for 'subject', 'goal', and 'knowledge' within SKILL.md. (2) Boundary markers: No explicit delimiters or safety warnings for user input are provided. (3) Capability inventory: None; the skill lacks tools, network access, or file-write capabilities. (4) Sanitization: Not applicable as no downstream tools are used. The lack of capabilities ensures that any potential injection in the data cannot be executed or cause harm.
Audit Metadata