clean-prose

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues or malicious patterns were detected. The skill acts as a proxy to a prose editing function and requires explicit human interaction, which is a secure design choice.
  • [PROMPT_INJECTION]: The skill processes user-supplied prose and file paths, which creates a surface for indirect prompt injection. 1. Ingestion points: Prose or file path passed as arguments to the skill (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: Calls the /prose-editing skill; no direct shell, file-system, or network capabilities are present in the analyzed files. 4. Sanitization: Absent. Security is maintained through the use of 'disable-model-invocation: true' and 'allow_implicit_invocation: false', which prevent the AI from being manipulated into triggering this skill without direct human intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 09:34 PM
Security Audit — agent-trust-hub — clean-prose