skills/simota/agent-skills/tome/Gen Agent Trust Hub

tome

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill establishes clear security boundaries, including a mandate to never write or modify code and an explicit refusal to generate documentation containing sensitive implementation details like auth internals or secret keys.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from git diffs, PR descriptions, and meeting transcripts to generate technical articles and records, which presents an indirect prompt injection surface. The risk is managed through specific structural guardrails.
  • Ingestion points: Technical data is gathered from external sources via partner agents (Trail, Launch, Lens) and direct user drafts as described in SKILL.md and reference/article-handoffs.md.
  • Boundary markers: The skill is required to use explicit [Inference: evidence] markers and LOW CONFIDENCE flags to isolate interpretations from source facts.
  • Capability inventory: Actionable capabilities are restricted to the creation and modification of markdown files. The skill lacks tools for shell command execution or network exfiltration.
  • Sanitization: A mandatory core contract requires the masking of credentials, client names, and non-public infrastructure details to prevent accidental data exposure in generated documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — tome