specialist-testing-testing-tool-evaluator

Pass

Audited by Gen Agent Trust Hub on Aug 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists exclusively of markdown instructions and does not contain any executable code, scripts, or binary files. It utilizes the platform's native Agent tool to delegate tasks to a specialized sub-persona.
  • [DATA_EXPOSURE]: Analysis of the skill body confirms no attempts to access sensitive system files (such as SSH keys, environment variables, or cloud credentials) and no hardcoded secrets or API tokens.
  • [REMOTE_CODE_EXECUTION]: No external URLs, remote script downloads (e.g., curl | bash), or third-party package installations (npm, pip) were detected in the instructions or metadata.
  • [PROMPT_INJECTION]: The sub-agent prompt provides functional, professional instructions for a technology assessment specialist. It does not contain adversarial patterns, jailbreak attempts, or instructions to ignore safety guidelines.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external information about software tools to generate reports.
  • Ingestion points: Processes "real-world scenarios and actual user data" as part of its core evaluation mission (SKILL.md).
  • Boundary markers: Absent; the prompt does not explicitly define delimiters for external data.
  • Capability inventory: The skill is limited to text generation and spawning sub-agents; it lacks native file-write or network capabilities.
  • Sanitization: Not explicitly defined in the provided instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 15, 2026, 08:50 PM
Security Audit — agent-trust-hub — specialist-testing-testing-tool-evaluator