03-understanding-of-assignment

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill contains no attempts to override agent behavior or bypass safety filters. It provides clear, constructive instructions for proposal drafting.
  • [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or unauthorized network operations were detected. The mentioned website and phone number are for author attribution and do not constitute a risk.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform any remote downloads. All references are to local files using relative paths within the repository (e.g., ../../SKILL.md).
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the execution of remote scripts or the installation of unverified packages.
  • [COMMAND_EXECUTION]: The skill is entirely instruction-based and does not invoke shell commands, subprocesses, or privilege escalation techniques.
  • [OBFUSCATION]: No hidden content, encoded strings (Base64/Hex), or deceptive characters (Zero-width/Homoglyphs) were found.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted data (ToR/RFP materials), it includes safeguards such as 'Return questions and a bounded interpretation; do not fill gaps as fact' and mandates labeling external premises, which effectively mitigates the risk of processing malicious instructions embedded in input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — 03-understanding-of-assignment