hybrid-event-design

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is composed strictly of instructional markdown files and contains no scripts, binaries, or automated shell commands. All logic is implemented via natural language instructions for the agent to follow during its interaction with the user.- [INDIRECT_PROMPT_INJECTION]: The skill provides an interaction model based on a structured interview to ingest user details about event planning. While this involves processing untrusted data, the risk is negligible as the skill lacks executable capabilities or network access.
  • Ingestion points: User responses to the 10-question interview in SKILL.md regarding event promises, attendee data, and constraints.
  • Boundary markers: The skill instructs the agent to establish a single 'promise' sentence as a reference point to validate all subsequent design choices, creating a logical boundary for decision-making.
  • Capability inventory: No subprocess calls, evaluation of code, file system writes, or network requests are present.
  • Sanitization: No specific sanitization is implemented beyond the instructional framing, as the skill produces only informational text outputs for the user.- [EXTERNAL_DOWNLOADS]: The skill references multiple 'sibling' tools (e.g., samber/dev-event-organizer-skills@event-production). These are internal cross-references to other skills authored by the same vendor (samber) and do not represent unauthorized external code execution or remote downloads.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — hybrid-event-design