skills/mtgvim/tiger-kit/tk-audit/Gen Agent Trust Hub

tk-audit

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill analyzes untrusted external data including PR reviews, issues, and CI logs. It includes a specific 'Retrieved Evidence Boundary' to treat such data as evidence rather than instructions.
  • Ingestion points: SKILL.md defines the ingestion of external context from logs, web content, and transcripts.
  • Boundary markers: Explicit instructions in SKILL.md command the agent to ignore instruction-like text within evidence.
  • Capability inventory: The skill is limited to read-only analysis and local file logging, with no implementation or remote publication authority.
  • Sanitization: Multiple files (SKILL.md, audit-playbook.md, executor-handoff.md) prohibit the replication of secret values or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 05:55 AM
Security Audit — agent-trust-hub — tk-audit