skills/shipshitdev/skills/wait-what/Gen Agent Trust Hub

wait-what

Pass

Audited by Gen Agent Trust Hub on Sep 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest data from CONTEXT.md and CONTEXT-MAP.md to define terminology. This creates a potential surface for instructions embedded in these files to influence the agent.\n
  • Ingestion points: The skill reads external glossary files CONTEXT.md and CONTEXT-MAP.md as described in the Contract section of SKILL.md.\n
  • Boundary markers: The instructions do not define clear boundaries or delimiters for the ingested file content.\n
  • Capability inventory: The skill has no file-write, network, or command execution capabilities; disable-model-invocation is explicitly set to true.\n
  • Sanitization: Content from the external files is not sanitized or filtered before processing.\n- [SAFE]: The skill does not contain executable code or perform network operations. All external references are for documentation purposes and point to the author's infrastructure or established development repositories.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 1, 2026, 08:22 AM
Security Audit — agent-trust-hub — wait-what