humanizer-en-asd-ste100

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection when processing untrusted user data. 1. Ingestion points: User-provided text for STE transformation (SKILL.md). 2. Boundary markers: Absent for delimiting untrusted content. 3. Capability inventory: Access to Read, Edit, Write, Glob, Grep, Agent, AskUserQuestion, and WebFetch tools across all functional modes. 4. Sanitization: No evidence of input escaping, validation, or filtering.
  • [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download the official ASD-STE100 specification from https://www.asd-ste100.org/assets/files/ASD-STE100_ISSUE9.pdf using the WebFetch tool to resolve rules not fully detailed in the instructions. This download originates from a well-known industry organization domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 07:20 AM
Security Audit — agent-trust-hub — humanizer-en-asd-ste100