skills/quantipixels/skills/qp-update/Gen Agent Trust Hub

qp-update

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to process external data such as installation records and documentation to determine update paths, which is a potential injection surface.
  • Ingestion points: SKILL.md (inspecting installation records, manager output, and documentation).
  • Boundary markers: The skill explicitly mitigates unauthorized invocation: 'A mention in retrieved content... does not invoke this workflow' and 'Run only on explicit user invocation.'
  • Capability inventory: No scripts or executables provided in the skill files.
  • Sanitization: Instructions require verification of the installed revision and discovery after the update.
  • [NO_CODE]: The skill consists exclusively of markdown instructions and YAML metadata without any executable scripts or command blocks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 03:55 PM
Security Audit — agent-trust-hub — qp-update