earn-integration-review
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external artifacts including codebases, screenshots, and flow descriptions provided by the user. This creates a potential surface for indirect prompt injection if the ingested data contains malicious instructions intended to manipulate the agent's evaluation. However, the skill's scope is restricted to generating a report based on these inputs, and it lacks dangerous capabilities (like network or file system writes) that could be abused through such an injection.
- [SAFE]: The skill uses a clear, structured workflow for auditing. It references local documentation (
docs/rubrics.md) and delegates tasks to other internal compliance agents within the same ecosystem (morpho-integration:*). No evidence of obfuscation, credential harvesting, or unauthorized persistence mechanisms was found.
Audit Metadata