eos-composition

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external text for composition review but lacks boundary markers or instructions to ignore commands within the analyzed content.
  • Ingestion points: The $ARGUMENTS placeholder at the end of SKILL.md appends user-provided text to the prompt.
  • Boundary markers: Absent. There are no delimiters or "ignore embedded instructions" warnings separating instructions from the data to be reviewed.
  • Capability inventory: The skill does not invoke any tools, network operations, or file-system write capabilities.
  • Sanitization: Absent. User input is appended to the instruction set without filtering or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:31 PM
Security Audit — agent-trust-hub — eos-composition