governance

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional Markdown and static reference data. It contains no executable scripts, shell commands, or network-active components.
  • [SAFE]: External references are limited to well-known institutional reports (African Development Bank and United Nations) and internal skill routing links. No suspicious remote code execution or package installation patterns are present.
  • [PROMPT_INJECTION]: No evidence of prompt injection or behavior override instructions was found. The instructions focus on domain-specific framing and methodology for governance proposals.
  • [DATA_EXFILTRATION]: The skill does not perform network operations or access sensitive system paths (e.g., .ssh, .env). The author contact information included in the acknowledgement is benign metadata.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process external documents such as Terms of Reference (ToRs) and assignment briefs (ingestion points), it maintains a 'read-only by default' capability contract and lacks any exploitable tools (no subprocess calls, file writes, or network access), mitigating the risk of indirect injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 06:11 AM
Security Audit — agent-trust-hub — governance