skills/saif-shines/doraval/ask-dora/Gen Agent Trust Hub

ask-dora

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user queries to decide which sub-module to load.
  • Ingestion points: User queries identified as 'the ask' in SKILL.md.
  • Boundary markers: No explicit delimiters or boundary markers are used to isolate user input from the router's logic.
  • Capability inventory: The skill loads other skills, recommends editing 'routine.yml', and suggests shell command executions (dora harness).
  • Sanitization: No input sanitization or validation mechanisms are implemented before processing the user input.
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download and install the 'scalekit-inc/authstack' package from a known developer service.
  • Evidence: Suggests running 'npx skills add scalekit-inc/authstack' and provides a link to 'https://docs.scalekit.com/dev-kit/build-with-ai/'.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 06:47 AM
Security Audit — agent-trust-hub — ask-dora