skills/shipshitdev/skills/skill-scout/Gen Agent Trust Hub

skill-scout

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources such as GitHub, package registries, and web search results. This presents a potential surface where instructions embedded in external content could influence the agent's evaluation.
  • Ingestion points: SKILL.md (Search External Sources) identifies data collection from web search, GitHub, and package registries.
  • Boundary markers: The skill relies on specific 'Vet Candidates' instructions to evaluate safety rather than using structural delimiters for external content.
  • Capability inventory: The skill operates in a read-only 'scout mode' and delegates actions like code creation or installation to other tools or processes requiring user confirmation.
  • Sanitization: The workflow incorporates manual verification steps and instructional checks for security posture.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the discovery of software packages and repositories from well-known registries and services. It identifies potential candidates for installation but enforces a manual confirmation step before any action is taken.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 04:53 AM
Security Audit — agent-trust-hub — skill-scout