ncr-writer

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill consists entirely of markdown instructions and text templates. It contains no executable scripts, binaries, or platform-specific command syntax.
  • [SAFE]: No network operations, data exfiltration patterns, or external downloads were detected. The skill does not communicate with any external servers.
  • [SAFE]: No credentials, secrets, or sensitive system file paths are hardcoded or accessed.
  • [SAFE]: No obfuscation techniques, hidden URLs, or malicious character encoding were found within the file content.
  • [PROMPT_INJECTION]: The skill instructions focus on defining a professional persona and enforce constraints that prioritize objective data over speculation. There are no attempts to bypass safety filters or extract system prompts.
  • [SAFE]: While the skill defines a workflow for ingesting external data (defect reports), it lacks any exploitable capabilities, making the risk of indirect prompt injection negligible.
  • Ingestion points: User-provided defect details and part identification fields in SKILL.md.
  • Boundary markers: None; rely on standard markdown structure.
  • Capability inventory: None; the skill has no tool access or execution environment permissions.
  • Sanitization: None required as the output is static text generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 03:52 AM
Security Audit — agent-trust-hub — ncr-writer