skill-security-auditor

Pass

Audited by Gen Agent Trust Hub on Jun 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues detected. The skill is purely instructional and establishes a methodology for safe agent configuration.
  • [PROMPT_INJECTION]: The static analysis detection of system prompt extraction is a false positive. The skill text mentions "attempts to reveal the system prompt" as a criterion for auditing third-party files, not as an instruction for the agent to reveal its own configuration. Additionally, while the skill processes untrusted input (an indirect prompt injection surface), the risk is negligible due to the complete absence of exploitable tools. 1. Ingestion points: auditee files provided by the user. 2. Boundary markers: none specified. 3. Capability inventory: no file, network, or process tools available. 4. Sanitization: none.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 18, 2026, 03:57 PM
Security Audit — agent-trust-hub — skill-security-auditor