distribution

Pass

Audited by Gen Agent Trust Hub on Aug 23, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute a local Node.js script located at scripts/run-state-check.js. This is used to verify the current state of the distribution analysis before proceeding and is a standard operational procedure within this skill's context.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data concerning Ideal Customer Profile (ICP) and community evidence to make distribution decisions. This represents an ingestion surface for potentially untrusted data.
  • Ingestion points: Data extracted from the run-state command, ICP definitions, and community reach lists.
  • Boundary markers: The instructions do not define specific delimiters for separating user-provided evidence from system instructions.
  • Capability inventory: The skill is restricted to analytical decision-making; it lacks tools for network operations or file system writes in the provided definition.
  • Sanitization: There is no evidence of input validation or sanitization for the processed evidence.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 23, 2026, 10:33 AM
Security Audit — agent-trust-hub — distribution