event-learning-expedition-design

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists entirely of Markdown and JSON configuration files. It does not contain any executable scripts (.py, .js, .sh), binary files, or package manifests.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines an interview workflow that ingests user-provided information to generate an expedition brief.
  • Ingestion points: User responses to nine interview questions defined in the 'Interview' section of SKILL.md.
  • Boundary markers: None; the skill instructions do not specify delimiters for user-provided answers.
  • Capability inventory: None; all referenced capabilities (transport, catering, legal) are explicitly routed to separate, external skills, and this skill performs no file, network, or system operations.
  • Sanitization: None; however, the risk is negligible due to the complete absence of system-level capabilities.
  • [SAFE]: The skill uses qualitative logic and decision rungs to guide event planning. It explicitly avoids hardcoding values or legal instruments, deferring to the host organization and professional counsel, which is a security best practice for this domain.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:13 PM
Security Audit — agent-trust-hub — event-learning-expedition-design