event-code-of-conduct

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a vulnerability surface for indirect prompt injection as it processes untrusted incident reports. 1. Ingestion points: Intake of reports from attendees, speakers, and volunteers (documented in references/incident-runbook-and-response-team.md). 2. Boundary markers: The instructions lack explicit delimiters or 'ignore' instructions for the raw report data. 3. Capability inventory: The skill performs text generation and context storage without access to high-risk commands or network operations. 4. Sanitization: The skill explicitly requires the use of code names to anonymize reports and restricts access to the response team.
  • [SAFE]: The skill is purely instructional and contains no executable scripts, obfuscated payloads, or persistence mechanisms. All external references are to legitimate documentation or other skills from the same vendor.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:13 PM
Security Audit — agent-trust-hub — event-code-of-conduct