void
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill evaluates external, potentially attacker-controlled data sources like usage logs, project tickets, and git history to justify recommendations for code or feature removal. A malicious actor could inject instructions into these data sources to bias the agent's assessment or trick it into proposing the removal of important (but non-security-critical) components.
- Ingestion points: Usage logs, git history, tickets, surveys, and stakeholder confirmation, as defined in
SKILL.md(Trigger Guidance) andreference/evaluation-criteria.md. - Boundary markers: The skill instructions in
SKILL.mdinclude explicit "Never" rules regarding safety-critical code (auth, encryption, input validation) and "Ask First" gates for public APIs or data-integrity targets. - Capability inventory: The skill is strictly advisory and read-only.
SKILL.mdexplicitly forbids the agent from editing code, documents, or executing deletion work directly, routing these tasks to other agents likeSweeporZen. - Sanitization: No specific data sanitization is mentioned; the skill relies on evidence-based quantification (Cost-of-Keeping score) and human-in-the-loop routing for its final recommendations.
Audit Metadata