fact-checker
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
- [METADATA_POISONING]: The skill includes a file named '.security-scan-passed' that asserts a successful security scan with a specific timestamp and hash. Following the assume-malicious posture, this is identified as a self-authoritative safety claim designed to influence security evaluations and is not considered a valid proof of safety. Additionally, there is an inconsistency between the provided author context ('nicepkg') and the entity referenced in the skill installation instructions ('daymade-skills').
- [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves processing untrusted content from user documents to drive web searches and file modifications, creating an attack surface for indirect prompt injection.
- Ingestion points: The agent identifies factual claims from user-provided documents in Step 1 of the workflow.
- Boundary markers: Absent. The instructions do not provide explicit delimiters or instructions for the agent to ignore potentially malicious directions embedded within the text being fact-checked.
- Capability inventory: The agent has capabilities to perform web searches and utilize the 'Edit' tool to modify files.
- Sanitization: Absent. There is no mention of filtering or sanitizing the extracted claims before they are used to build search queries or proposed as document corrections.
Audit Metadata