event-vip-management
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill follows security and privacy best practices for its domain. It explicitly instructs users to set deletion dates for guest rosters, limit data circulation to a need-to-know basis, and avoid recording subjective judgments about individuals. All external skill references are to the author's own ecosystem.- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external requirements from guest offices or protective details. While this represents a potential surface for indirect prompt injection, the skill includes structural defenses such as a qualification test that requires specific obligation types and instructions to treat requirements as quoted data rather than instructions. Evidence: Ingestion points in SKILL.md (Interview Q3-Q5) and references/discretion-and-escort-mechanics.md (Liaison intake step 2); Boundary markers in references/guest-qualification-and-roster.md (The Test); Capabilities include generating a guest brief and recording per edition to persistent memory; No specific sanitization beyond quoting is mandated.
Audit Metadata