skill-scout

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface because it is designed to process untrusted data from external sources during its research phase.
  • Ingestion points: Public GitHub repositories, package registries (NPM/PyPI), and web search results (referenced in SKILL.md sections 3 and 4).
  • Boundary markers: Absent. The skill does not define specific delimiters for separating searched content from its own instructions.
  • Capability inventory: The skill is limited to read-only searches and candidate ranking; it explicitly requires confirmation before performing any installation or imports.
  • Sanitization: Not explicitly defined in the instructions, though the skill mandates a 'Vet Candidates' step to check for side effects, shell commands, and credential handling before adoption.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 01:13 PM
Security Audit — agent-trust-hub — skill-scout