event-sponsor-agreement

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill contains a vulnerability surface for indirect prompt injection as it ingests untrusted user input to generate legal term sheets.
  • Ingestion points: The Interview section in SKILL.md identifies nine specific questions that collect untrusted data from the user regarding event details, pricing, and perks.
  • Boundary markers: The skill includes robust boundary markers, specifically mandatory disclaimers at the start and end of its output stating that it does not provide legal advice and requires review by qualified counsel.
  • Capability inventory: The skill has no capability for command execution, network operations, or file system modifications, as no executable scripts or platform tools are defined in the provided files.
  • Sanitization: The skill relies on the human-in-the-loop requirement (legal review) for final sanitization and verification of the generated content.
  • [SAFE]: No malicious code, base64 obfuscation, zero-width characters, or homoglyph attacks were found. References to other skills in the collection (e.g., samber/dev-event-organizer-skills@event-sponsor-pricing) are legitimate vendor-specific resource invocations that align with the skill's stated purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — event-sponsor-agreement