pv-signal

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions focus entirely on linguistic transformation and tone adjustment. No patterns typical of prompt injection, such as instructions to ignore prior rules or bypass safety filters, were found.
  • [DATA_EXFILTRATION]: The skill does not use any tools or commands that could facilitate network communication or access to sensitive user data like credentials or SSH keys.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted user input by design (draft prose).
  • Ingestion points: User-provided text in SKILL.md processing.
  • Boundary markers: Not explicitly defined in the instructions.
  • Capability inventory: Restricted to text rewriting and formatting; no access to shell, filesystem, or network.
  • Sanitization: None identified, but the lack of executable capabilities mitigates the risk.
  • [COMMAND_EXECUTION]: There are no shell commands or subprocess calls defined in the skill or its associated documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 11:30 AM
Security Audit — agent-trust-hub — pv-signal