risk-assessor
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is purely instructional and provides a framework for vulnerability assessment without introducing any executable scripts or binary dependencies.- [PROMPT_INJECTION]: No malicious injection patterns, safety bypass attempts, or instructions to ignore system guidelines were detected. The skill includes appropriate constraints on when the scoring format should not be applied.- [DATA_EXFILTRATION]: The skill does not perform network requests or attempt to access sensitive system files (e.g., credentials, SSH keys, or environment variables). While it handles sensitive data descriptions (PCI/PII) for scoring purposes, it does not instruct the agent to send this data externally.- [REMOTE_CODE_EXECUTION]: There are no patterns indicating the download or execution of remote code. The skill does not use package managers or dynamic code execution environments.- [COMMAND_EXECUTION]: No shell commands or system-level operations are present in the instructions or benchmarks.- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied vulnerability descriptions. While it lacks explicit boundary markers for this input, it does not possess any dangerous capabilities (like file writing or network access) that could be abused via a poisoned input. The surface is limited to analytical reporting.
Audit Metadata