fabric-advisor

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements an ambient advisor that monitors agent activity. It is restricted to using "read-only native tools" to inspect the workspace, which prevents unauthorized modifications or destructive actions.
  • [SAFE]: Although the skill references a setup file in a sibling directory ("../fabric-ambient/references/setup.md"), this is a standard configuration pattern within the Fabric framework and does not target sensitive system or user files.
  • [PROMPT_INJECTION]: The advisor agent processes "parent-session event and recent transcript" (SKILL.md), which serves as an entry point for untrusted data. No specific boundary markers are defined. The agent has "read-only native tools" (SKILL.md) to "Inspect the workspace". No sanitization logic is specified. The risk is minimized by the advisor's read-only status and limited output scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 11:34 AM
Security Audit — agent-trust-hub — fabric-advisor