skills/sharpdeveye/maestro/reflect/Gen Agent Trust Hub

reflect

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external log files which could theoretically contain instructions intended to influence the agent's behavior.
  • Ingestion points: Reads .maestro/audit.jsonl and .maestro/decisions.jsonl from the project root (SKILL.md).
  • Boundary markers: Absent. The instructions do not define specific delimiters or provide guidance to the agent to disregard instructions embedded within the logs.
  • Capability inventory: No high-risk capabilities such as arbitrary command execution, network operations, or file-writing were identified in the skill instructions.
  • Sanitization: Absent. The skill instructions direct the agent to analyze the log data directly for the scorecard without prior validation or filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 08:01 PM
Security Audit — agent-trust-hub — reflect