llm-risk-assess

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides legitimate security assessment methodologies based on industry-standard OWASP guidelines. No malicious patterns, obfuscation, or unauthorized access attempts were detected in the provided markdown file.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a security auditing workflow that ingests untrusted data from external applications, including architecture documentation, data flows, and test logs (SKILL.md).
  • Ingestion points: Steps 1 (Architecture & Threat Modeling) and 4 (Red Team Testing) involve processing data from external sources.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded prompts are provided in the workflow.
  • Capability inventory: The skill allows the use of Bash, WebFetch, Read, and Agent tools, which could be leveraged if the agent follows instructions hidden within analyzed documents.
  • Sanitization: The instructions do not specify any sanitization, validation, or escaping of the external content processed during the audit.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 09:32 PM
Security Audit — agent-trust-hub — llm-risk-assess