verify
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted trajectories which may contain malicious instructions. It mitigates this by requiring explicit boundary markers (e.g., TRACE_A START/END) and providing specific instructions to the agent to treat fenced content as data only and ignore any embedded narration or instructions.
- [COMMAND_EXECUTION]: The skill facilitates the generation and execution of agent trajectories. To prevent unauthorized modifications or privilege escalation, it mandates the use of isolated worktrees or copies and strictly prohibits same-tree parallel writes.
- [SAFE]: The implementation follows academic best practices for best-of-N sampling and logprob-based verification, with no evidence of credential exfiltration, obfuscation, or unauthorized network access.
Audit Metadata