ncr-writer
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of markdown instructions and text templates. It contains no executable scripts, binaries, or platform-specific command syntax.
- [SAFE]: No network operations, data exfiltration patterns, or external downloads were detected. The skill does not communicate with any external servers.
- [SAFE]: No credentials, secrets, or sensitive system file paths are hardcoded or accessed.
- [SAFE]: No obfuscation techniques, hidden URLs, or malicious character encoding were found within the file content.
- [PROMPT_INJECTION]: The skill instructions focus on defining a professional persona and enforce constraints that prioritize objective data over speculation. There are no attempts to bypass safety filters or extract system prompts.
- [SAFE]: While the skill defines a workflow for ingesting external data (defect reports), it lacks any exploitable capabilities, making the risk of indirect prompt injection negligible.
- Ingestion points: User-provided defect details and part identification fields in SKILL.md.
- Boundary markers: None; rely on standard markdown structure.
- Capability inventory: None; the skill has no tool access or execution environment permissions.
- Sanitization: None required as the output is static text generation.
Audit Metadata