sepia-hemingway

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill includes explicit defensive instructions for the agent to treat target content as untrusted data rather than instructions or authority, which mitigates indirect prompt injection risks.
  • [SAFE]: File system access is tightly scoped to specific relative sibling paths (../sepia/) within the plugin's directory. It explicitly prohibits searching home directories, global skill roots, or external registries.
  • [SAFE]: The skill adheres to the principle of least privilege by explicitly stating it grants no tool, network, or external-action authority to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 07:55 AM
Security Audit — agent-trust-hub — sepia-hemingway