ask-to

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is purely instructional and serves to organize and recommend workflows within the repository. It contains no executable code, shell scripts, or commands that interact with the host system.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a theoretical attack surface because it processes potentially untrusted repository state and user intent to generate routing recommendations. However, because the skill is limited to producing Markdown artifacts and reasoning, and lacks dangerous capabilities like code execution or network access, the operational risk is negligible. 1. Ingestion points: Processes user intent, current repository state, and the registry of available skills (SKILL.md files). 2. Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore embedded content in the ingested repository data. 3. Capability inventory: The skill is restricted to generating reasoning artifacts and Markdown documentation as defined in the frontmatter. 4. Sanitization: No sanitization or filtering is applied to the repository data processed during routing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 03:00 AM
Security Audit — agent-trust-hub — ask-to