aya-source-investigation

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from external sources during its fact-checking process, which constitutes a potential indirect prompt injection surface.\n
  • Ingestion points: Search results and third-party web content as specified in SKILL.md.\n
  • Boundary markers: No explicit delimiters or ignore instructions for the fetched content.\n
  • Capability inventory: Limited to browsing and information retrieval; no subprocess, file-write, or network exfiltration capabilities associated with the ingested data.\n
  • Sanitization: Instructions to paraphrase findings and limit direct quotations help mitigate risks.\n- [EXTERNAL_DOWNLOADS]: The documentation includes a link to a GitHub repository (github.com/N0zoM1z0/gensokyo-monochrome-heart) to explain the character-to-workflow mapping. This is a reference to a well-known service and belongs to the identified skill author context.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 04:34 PM
Security Audit — agent-trust-hub — aya-source-investigation