ai-product

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill contains strings typically associated with prompt injection, such as "Ignore all previous instructions" and "reveal your system prompt." These instances are identified as part of a documentation section titled "User input directly in prompts without sanitization," which aims to educate developers on how to prevent such attacks. They are not active attempts to override agent behavior.
  • [DATA_EXFILTRATION]: Analysis of the skill reveals no exfiltration mechanisms. It includes educational guidance on identifying the risks of exposing sensitive data and provides patterns for monitoring usage costs.
  • [REMOTE_CODE_EXECUTION]: No patterns of remote script execution or dynamic code evaluation from untrusted sources were found. The code snippets provided are for standard application logic using well-known libraries like Zod and Tiktoken.
  • [SAFE]: The overall intent and implementation of the skill are educational and focus on improving the reliability and security of AI-integrated software.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 08:36 AM
Security Audit — agent-trust-hub — ai-product