03-understanding-of-assignment
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill contains no attempts to override agent behavior or bypass safety filters. It provides clear, constructive instructions for proposal drafting.
- [DATA_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or unauthorized network operations were detected. The mentioned website and phone number are for author attribution and do not constitute a risk.
- [EXTERNAL_DOWNLOADS]: The skill does not perform any remote downloads. All references are to local files using relative paths within the repository (e.g.,
../../SKILL.md). - [REMOTE_CODE_EXECUTION]: There are no patterns involving the execution of remote scripts or the installation of unverified packages.
- [COMMAND_EXECUTION]: The skill is entirely instruction-based and does not invoke shell commands, subprocesses, or privilege escalation techniques.
- [OBFUSCATION]: No hidden content, encoded strings (Base64/Hex), or deceptive characters (Zero-width/Homoglyphs) were found.
- [INDIRECT_PROMPT_INJECTION]: While the skill ingests untrusted data (ToR/RFP materials), it includes safeguards such as 'Return questions and a bounded interpretation; do not fill gaps as fact' and mandates labeling external premises, which effectively mitigates the risk of processing malicious instructions embedded in input data.
Audit Metadata