event-community-building

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process data from untrusted sources, creating a vulnerability surface.
  • Ingestion points: As detailed in references/cadence-and-content-shapes.md, the skill recommends using "members' own posts" as source material for community digests.
  • Boundary markers: The instructions define "sibling boundaries" to scope agent behavior, but they do not provide specific delimiters or instructions to ignore potential commands embedded within member-generated content.
  • Capability inventory: The skill's capabilities are limited to generating textual plans, inventories, and handoff documents. It does not perform shell execution, file system modifications, or network operations.
  • Sanitization: The skill does not mention or implement any sanitization, filtering, or escaping for the content ingested from community members.
  • [DATA_EXFILTRATION]: The skill provides procedures for the movement of sensitive user data.
  • Evidence: In references/community-asset-handoff.md, the skill provides instructions to "Export the member list" and document its "format, location, and consent basis."
  • Risk: While these instructions support legitimate administrative handovers between organizers, they involve the handling and transfer of Personally Identifiable Information (PII) such as attendee email lists.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:13 PM
Security Audit — agent-trust-hub — event-community-building