hackathon-brief-design

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious patterns intended to bypass safety guardrails or override core agent behavior were detected. The instructions use standard, benign language to define the skill's logic.
  • [DATA_EXPOSURE]: There is no evidence of hardcoded credentials, sensitive file path access (e.g., .ssh, .aws), or unauthorized data collection.
  • [DATA_EXFILTRATION]: The skill does not perform network operations to external domains for the purpose of exfiltration. All referenced URLs (github.com, spaceappschallenge.org) are well-known and relevant to the skill's purpose.
  • [REMOTE_CODE_EXECUTION]: No patterns for remote script execution or unauthorized command execution were found. References to other skills by the same author ('samber') represent modular skill design rather than RCE.
  • [OBFUSCATION]: The skill body and metadata contain no encoded content, zero-width characters, or homoglyph substitutions designed to hide malicious intent.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not utilize dynamic context injection or shell-command placeholders in its configuration.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (user interview answers and previous rules), it lacks the dangerous capabilities (such as file-writing or network exfiltration) necessary to exploit this attack surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — hackathon-brief-design