event-community-building
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process data from untrusted sources, creating a vulnerability surface.
- Ingestion points: As detailed in
references/cadence-and-content-shapes.md, the skill recommends using "members' own posts" as source material for community digests. - Boundary markers: The instructions define "sibling boundaries" to scope agent behavior, but they do not provide specific delimiters or instructions to ignore potential commands embedded within member-generated content.
- Capability inventory: The skill's capabilities are limited to generating textual plans, inventories, and handoff documents. It does not perform shell execution, file system modifications, or network operations.
- Sanitization: The skill does not mention or implement any sanitization, filtering, or escaping for the content ingested from community members.
- [DATA_EXFILTRATION]: The skill provides procedures for the movement of sensitive user data.
- Evidence: In
references/community-asset-handoff.md, the skill provides instructions to "Export the member list" and document its "format, location, and consent basis." - Risk: While these instructions support legitimate administrative handovers between organizers, they involve the handling and transfer of Personally Identifiable Information (PII) such as attendee email lists.
Audit Metadata