devrel-budget-allocation
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONPERSISTENCE
Full Analysis
- [SAFE]: The skill is instructional and data-processing focused. It does not exhibit malicious patterns, unauthorized network operations, or credential harvesting.- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface by ingesting untrusted data during the budget interview process. Evidence chain: (1) Ingestion points: User input during the interview described in
SKILL.md; (2) Boundary markers: No delimiters or explicit instructions to ignore embedded commands are present; (3) Capability inventory: The skill has no dangerous capabilities such as shell execution, file system modification, or network access; (4) Sanitization: No input validation or filtering is specified. The risk is minimal due to the lack of exploitable actions.- [PERSISTENCE]: The skill suggests utilizing the agent platform's persistent memory to store budget envelopes and verdicts across annual cycles. This is a functional requirement for the task and not a malicious persistence mechanism such as a cron job or shell profile modification.
Audit Metadata