ask-matt

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill establishes workflows that ingest untrusted external data, such as user-submitted bug reports and feature requests, which could contain malicious instructions.
  • Ingestion points: Processes external issues, bug reports, and project documentation (CONTEXT.md).
  • Boundary markers: Explicitly defines 'Phase Boundaries' in PHASE-BOUNDARIES.md to manage context and mitigate instruction bleed between tasks, emphasizing the distinction between first-hand and second-hand information.
  • Capability inventory: Routes to other skills capable of code implementation, file manipulation, and issue management.
  • Sanitization: No specific sanitization or filtering logic is described for the external inputs.
  • [SAFE]: The skill provides high-level process documentation and meta-instructions for routing without including any executable scripts or hidden commands.
  • [EXTERNAL_DOWNLOADS]: Includes a plain-text link to external documentation at aihero.dev to define technical terminology such as 'smart zones'.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 03:10 PM
Security Audit — agent-trust-hub — ask-matt