skills/simota/agent-skills/summon/Gen Agent Trust Hub

summon

Pass

Audited by Gen Agent Trust Hub on Aug 13, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No evidence of instructions attempting to bypass safety filters or override agent behavior was found. The skill includes explicit instructions to refuse deceptive uses and maintain role boundaries.
  • [DATA_EXFILTRATION]: The skill does not perform network operations to untrusted domains or access sensitive system files like credentials or SSH keys.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote scripts, nor does the skill use dynamic execution functions like eval or exec.
  • [CREDENTIALS_UNSAFE]: No hardcoded API keys, tokens, or private secrets were detected in the source code or reference files. Guidance for managing profiles suggests local workspace storage only.
  • [OBFUSCATION]: The skill uses clear, human-readable markdown and YAML with no hidden characters, Base64-encoded instructions, or homoglyph substitutions.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes external information for figure research, it mitigates injection risks by requiring all claims to be tagged with attestation tiers (ATTESTED, INFERRED, SPECULATIVE) and running a mandatory 'Ethics Gate' that refuses deceptive or undocumented uses.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 13, 2026, 09:28 AM
Security Audit — agent-trust-hub — summon