atlas-contract

Pass

Audited by Gen Agent Trust Hub on Jun 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional logic and markdown templates. No executable scripts, binary files, or external dependencies are included.
  • [PROMPT_INJECTION]: The instructions are designed to strengthen agent alignment. There are no patterns that attempt to bypass system safety filters or override global instructions for malicious purposes. The skill includes specific safeguards against context drift and silent requirement modification.
  • [DATA_EXFILTRATION]: No network operations (curl, wget, fetch) or data transmission patterns are present. The skill focuses on managing internal agent state and project documentation.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides instructions for reading an Atlas.md file as project memory. It explicitly warns to treat this file as 'untrusted project memory' and includes constraints to prevent it from overriding safety rules or system policies, effectively mitigating the risk of indirect injection from workspace files.
  • [COMMAND_EXECUTION]: No shell commands, subprocess calls, or privilege escalation patterns were identified in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 30, 2026, 01:47 PM
Security Audit — agent-trust-hub — atlas-contract