taste
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [NO_CODE]: The skill consists exclusively of markdown documentation and instructional references. It does not include any executable scripts, binary files, or system commands.
- [SAFE]: No network operations, external data fetching, or sensitive file system access is performed by the skill. All operations are confined to the conversational context.
- [PROMPT_INJECTION]: The skill processes untrusted user-supplied artifacts for analysis, which represents an ingestion point for indirect prompt injection.
- Ingestion points: User-provided text, code, or design artifacts in
SKILL.md(audit mode). - Boundary markers: None identified in the instructional text for separating user content from instructions.
- Capability inventory: No tools or high-privilege capabilities (e.g., shell access, network requests) are utilized by this skill.
- Sanitization: No input validation or content sanitization mechanisms are implemented.
- [SAFE]: The skill implements safety best practices through 'Auto-clarity exceptions' that instruct the agent to suspend the judgment persona and prioritize transparency for security warnings, destructive operation confirmations, and critical procedures.
Audit Metadata