governance
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of instructional Markdown and static reference data. It contains no executable scripts, shell commands, or network-active components.
- [SAFE]: External references are limited to well-known institutional reports (African Development Bank and United Nations) and internal skill routing links. No suspicious remote code execution or package installation patterns are present.
- [PROMPT_INJECTION]: No evidence of prompt injection or behavior override instructions was found. The instructions focus on domain-specific framing and methodology for governance proposals.
- [DATA_EXFILTRATION]: The skill does not perform network operations or access sensitive system paths (e.g., .ssh, .env). The author contact information included in the acknowledgement is benign metadata.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process external documents such as Terms of Reference (ToRs) and assignment briefs (ingestion points), it maintains a 'read-only by default' capability contract and lacks any exploitable tools (no subprocess calls, file writes, or network access), mitigating the risk of indirect injection attacks.
Audit Metadata