seda-sigidi

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for persona and identity management. It incorporates security-conscious instructions, specifically directing the agent to recognize secrets in session data, quote around them, and ensure they are never printed, copied, or stored.
  • [SAFE]: The skill explicitly limits its scope in the frontmatter and body, stating it does not install, activate, publish, commit, or push changes to providers or Git repositories, which reduces the risk of unauthorized external actions.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted external data sources to define agent behavior, representing a standard injection surface.
  • Ingestion points: The skill mines session records, memory files, and existing instructions (SKILL.md, Section 2).
  • Boundary markers: Information is filtered through a structured template (references/soul-template.md) which requires confirmed evidence for each section.
  • Capability inventory: The skill possesses file read and write capabilities for host configuration targets when using the integrate path (SKILL.md, Section 1 and 4).
  • Sanitization: The agent is instructed to run a discovery pass to confirm inferred patterns and to mask secrets found in session data (SKILL.md, Section 2).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 11:16 PM
Security Audit — agent-trust-hub — seda-sigidi