skills/quantipixels/skills/seda-spec/Gen Agent Trust Hub

seda-spec

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data sources to generate its output, creating a potential surface for indirect prompt injection.\n
  • Ingestion points: Conversation logs, issue trackers, policy documents, and existing specifications referenced in the input.\n
  • Boundary markers: The agent is instructed to distinguish between "confirmed behavior" and "inference," and to document "confirmed authority" versus "unresolved questions," which provides a logical structure to identify and isolate untrusted content.\n
  • Capability inventory: The skill can invoke sub-agents and use the akosile tool to write to workspace records.\n
  • Sanitization: There are no explicit instructions for sanitizing or escaping the input data before processing.\n\n- [COMMAND_EXECUTION]: The instructions describe interactions with external tools and sub-agents to perform specialized tasks.\n
  • Evidence: The skill delegates work to sub-agents named amose, iwadi, arojinle, and architect. It also records behavior specifications via the akosile tool using specific parameters (owner: seda-spec, record_type: behavior-spec). These represent standard modular agent interactions within the vendor's ecosystem.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 11:40 AM
Security Audit — agent-trust-hub — seda-spec