skills/simota/agent-skills/echo/Gen Agent Trust Hub

echo

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data in the form of UI screenshots and code for the purpose of evaluation. While the skill's capabilities are restricted to generating reports and does not involve direct execution of this data, there is an inherent risk that instructions embedded within the processed UI could attempt to influence the agent's evaluation outcomes (e.g., artificially inflating sentiment scores). \n- [COMMAND_EXECUTION]: The skill invokes platform-specific CLI tools, specifically codex and agy, to orchestrate parallel evaluations across different AI engines. These commands are executed as part of the 'multi' recipe and are used to fulfill the skill's core functionality within its intended deployment environment. \n- [DYNAMIC_EXECUTION]: The skill uses dynamic prompt generation to delegate tasks to subagents. It includes detailed templates for constructing instructions for other LLMs, which is a standard pattern for complex agentic workflows involving multi-engine triangulation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — echo