sepia-hemingway
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill includes explicit defensive instructions for the agent to treat target content as untrusted data rather than instructions or authority, which mitigates indirect prompt injection risks.
- [SAFE]: File system access is tightly scoped to specific relative sibling paths (
../sepia/) within the plugin's directory. It explicitly prohibits searching home directories, global skill roots, or external registries. - [SAFE]: The skill adheres to the principle of least privilege by explicitly stating it grants no tool, network, or external-action authority to the agent.
Audit Metadata