execution-policy

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts external inputs (requested action and skill manifest) which creates an indirect prompt injection surface. 1. Ingestion points: Inputs 'requested action' and 'skill manifest' in SKILL.md. 2. Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands in the processed data. 3. Capability inventory: The skill is restricted to read-only side effects and produces reasoning artifacts only; it possesses no capabilities for command execution, network access, or file system modifications. 4. Sanitization: No sanitization or validation logic is present for the input data.
  • [NO_CODE]: The skill consists entirely of instructional content and metadata, with no scripts, executable binaries, or external dependencies.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 02:59 AM
Security Audit — agent-trust-hub — execution-policy