dojo-elena-verna
Pass
Audited by Gen Agent Trust Hub on Sep 22, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The analyzed skill is composed entirely of instructional Markdown files and documentation regarding business growth, pricing, and product strategy. No shell scripts, binaries, or configuration files for package managers were found. The skill does not attempt to perform network operations, access sensitive files, or execute system commands.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process user questions to route queries to specific expert frameworks. Analysis of the attack surface shows no significant risk of exploitation.\n
- Ingestion points: User queries (e.g., "ask Verna" or topical questions) processed via the routing logic defined in
SKILL.md.\n - Boundary markers: The instructions in
SKILL.mdandpersona.mdprovide clear constraints, mandating that the agent "Never invoke a framework that isn't in the topic files you loaded" and "Answer in that expert's voice using only the substance in the files you loaded."\n - Capability inventory: The skill is limited to reading its own documentation and generating text responses. It lacks the ability to execute subprocesses, write to the file system, or initiate network connections.\n
- Sanitization: The expert persona instructions include heuristics that discourage fabrication and synthesis, requiring the agent to reflect the expert's specific viewpoints without hedging or blending voices.
Audit Metadata