think-pairwise-comparison

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides a structured thinking framework for performing qualitative ranking. It is composed entirely of markdown instructions and metadata, with no associated script files, binary executables, or remote dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a process for ranking user-provided options, which is a standard data ingestion surface. 1. Ingestion points: The skill reads items to rank from the user's prompt (SKILL.md, Instructions). 2. Boundary markers: The output template (references/TEMPLATE.md) does not define specific delimiters for the untrusted item names. 3. Capability inventory: The skill does not invoke any tools, network operations, or file system commands. 4. Sanitization: No sanitization or escaping is applied to the input items. However, since the skill has no exploitable capabilities, this ingestion surface poses no practical security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 04:39 PM
Security Audit — agent-trust-hub — think-pairwise-comparison