source-trace-wx
Pass
Audited by Gen Agent Trust Hub on Aug 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The instructions in the skill are focused on factual verification and documentation. No code, scripts, or suspicious command patterns were found.
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from web searches to verify claims, which represents a surface for indirect prompt injection. However, the behavior is limited to documenting source links. Ingestion points: Web search results and conversation history (SKILL.md). Boundary markers: Absent. Capability inventory: Writing Markdown files to the 'sources/' directory (SKILL.md). Sanitization: Absent.
Audit Metadata