compress

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user data such as prompts, specifications, and notes to perform compression. This creates an attack surface where malicious instructions embedded in the source text could attempt to influence the agent's behavior. 1. Ingestion points: The skill accepts user-supplied text for compression as defined in SKILL.md. 2. Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands within the input text provided in the skill definition. 3. Capability inventory: The skill is restricted to natural language processing and does not invoke external tools, subprocesses, or network operations. 4. Sanitization: No sanitization, validation, or escaping of the input content is implemented.
  • [NO_CODE]: The skill consists entirely of configuration files and natural language instructions. No executable scripts, binaries, or complex automation logic are included, which limits the potential for direct system exploitation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:08 PM
Security Audit — agent-trust-hub — compress