specialist-testing-testing-tool-evaluator
Pass
Audited by Gen Agent Trust Hub on Aug 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists exclusively of markdown instructions and does not contain any executable code, scripts, or binary files. It utilizes the platform's native Agent tool to delegate tasks to a specialized sub-persona.
- [DATA_EXPOSURE]: Analysis of the skill body confirms no attempts to access sensitive system files (such as SSH keys, environment variables, or cloud credentials) and no hardcoded secrets or API tokens.
- [REMOTE_CODE_EXECUTION]: No external URLs, remote script downloads (e.g., curl | bash), or third-party package installations (npm, pip) were detected in the instructions or metadata.
- [PROMPT_INJECTION]: The sub-agent prompt provides functional, professional instructions for a technology assessment specialist. It does not contain adversarial patterns, jailbreak attempts, or instructions to ignore safety guidelines.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external information about software tools to generate reports.
- Ingestion points: Processes "real-world scenarios and actual user data" as part of its core evaluation mission (SKILL.md).
- Boundary markers: Absent; the prompt does not explicitly define delimiters for external data.
- Capability inventory: The skill is limited to text generation and spawning sub-agents; it lacks native file-write or network capabilities.
- Sanitization: Not explicitly defined in the provided instructions.
Audit Metadata