skill-fusion

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill is entirely composed of natural language instructions and structural templates. It does not contain any shell scripts, binary files, or code-based tools.
  • [SAFE]: Analysis of the skill instructions revealed no evidence of prompt injection, data exfiltration, obfuscation, or persistence mechanisms.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process other skills ('parent skills') which may come from untrusted sources.
  • Ingestion points: Untrusted parent skill definitions are provided as input in SKILL.md.
  • Boundary markers: Absent; the fusion process does not specify the use of delimiters to wrap the parent skills.
  • Capability inventory: None; the skill has no access to subprocesses, file writing, or network operations in SKILL.md.
  • Sanitization: Absent; there are no instructions to validate or sanitize the input content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 05:56 PM
Security Audit — agent-trust-hub — skill-fusion