virtual-event-production

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill is composed exclusively of Markdown instructions and JSON evaluation cases. It does not include any scripts (Python, JavaScript, shell), binaries, or tool configurations that could execute code.
  • [SAFE]: The skill does not perform any network operations, access sensitive file paths, or attempt to exfiltrate data. References to third-party platforms like Discord, Slack, Google Meet, and OBS are provided as part of the strategic advice for event organizers. The instructions refer to other capabilities within the 'samber' vendor ecosystem (e.g., samber/dev-event-organizer-skills@event-production) for cross-functional event coordination.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to interact with users through a structured interview to determine event requirements. While this represents a surface for ingesting untrusted data, the skill possesses no dangerous capabilities to exploit.
  • Ingestion points: The 'Interview' section in SKILL.md identifies 11 questions where user-provided data enters the agent's context.
  • Boundary markers: The instructions use logical 'Menus' and 'Workflow' steps to constrain how the agent processes inputs.
  • Capability inventory: No subprocess execution, file system modification, or network requests are present in any of the provided files.
  • Sanitization: The skill relies on natural language reasoning and ranking logic rather than programmatic sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — virtual-event-production