tipkit

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTIONNO_CODE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill's main instruction file (SKILL.md) directs the agent to fetch additional documentation from an external mirror at https://sosumi.ai if the required information is not found in the local reference files.\n- [PROMPT_INJECTION]: The instruction to ingest and process documentation from a third-party domain creates a potential surface for indirect prompt injection.\n
  • Ingestion points: SKILL.md instructs the agent to access documentation via https://sosumi.ai/documentation/tipkit/... when needed.\n
  • Boundary markers: Absent; there are no instructions to use delimiters or ignore instructions embedded in the external content.\n
  • Capability inventory: The skill is documentation-only and does not include any scripts or tools that perform command execution, file system modifications, or network operations.\n
  • Sanitization: Absent; the skill does not define methods to validate or sanitize the incoming markdown content.\n- [NO_CODE]: The skill consists entirely of markdown documentation and YAML configuration; no executable code (Python, JavaScript, or shell scripts) is included in the package.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 03:29 PM
Security Audit — agent-trust-hub — tipkit