dojo-lulu-cheng

Pass

Audited by Gen Agent Trust Hub on Sep 22, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of Markdown-based instructions and frameworks. No scripts (.sh, .py, .js), binaries, or other executable files are included in the skill package.
  • [SAFE]: There is no evidence of network operations, hardcoded credentials, or access to sensitive system paths. The skill's operations are confined to reading the provided text files and generating responses based on them.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection because its primary function involves reviewing untrusted data provided by the user (e.g., 'Critique this comms plan').
  • Ingestion points: User-provided documents, plans, or drafts submitted for review or critique (SKILL.md).
  • Boundary markers: The instructions lack explicit delimitation or 'ignore embedded instructions' directives for the content being reviewed.
  • Capability inventory: The skill has no defined tools (no allowed-tools in frontmatter) and no script-based capabilities; its only capability is text generation.
  • Sanitization: There is no evidence of sanitization or filtering applied to user-provided content.
  • Assessment: While the surface exists, the lack of any system tools or network access makes the actual risk to the environment negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 22, 2026, 03:31 PM
Security Audit — agent-trust-hub — dojo-lulu-cheng