skills/moontory/skills/reflect/Gen Agent Trust Hub

reflect

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted session transcripts which may contain malicious instructions. It implements significant mitigations by explicitly instructing sub-agents to ignore directives within the transcript and treat the data as untrusted.
  • [COMMAND_EXECUTION]: While the skill orchestrates agents that may use tools (shell, MCP, etc.), it mandates explicit user approval for every proposed external write or skill modification.
  • [REMOTE_CODE_EXECUTION]: The skill mentions external models and MCP tools, but does not provide mechanisms for unverified code execution. Access to external data (tickets, traces) is scoped to context referenced in the transcript.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 03:21 PM
Security Audit — agent-trust-hub — reflect