fact-checker

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONING
Full Analysis
  • [METADATA_POISONING]: The skill includes a file named '.security-scan-passed' that asserts a successful security scan with a specific timestamp and hash. Following the assume-malicious posture, this is identified as a self-authoritative safety claim designed to influence security evaluations and is not considered a valid proof of safety. Additionally, there is an inconsistency between the provided author context ('nicepkg') and the entity referenced in the skill installation instructions ('daymade-skills').
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary workflow involves processing untrusted content from user documents to drive web searches and file modifications, creating an attack surface for indirect prompt injection.
  • Ingestion points: The agent identifies factual claims from user-provided documents in Step 1 of the workflow.
  • Boundary markers: Absent. The instructions do not provide explicit delimiters or instructions for the agent to ignore potentially malicious directions embedded within the text being fact-checked.
  • Capability inventory: The agent has capabilities to perform web searches and utilize the 'Edit' tool to modify files.
  • Sanitization: Absent. There is no mention of filtering or sanitizing the extracted claims before they are used to build search queries or proposed as document corrections.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:04 AM
Security Audit — agent-trust-hub — fact-checker