skills/simota/agent-skills/void/Gen Agent Trust Hub

void

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill evaluates external, potentially attacker-controlled data sources like usage logs, project tickets, and git history to justify recommendations for code or feature removal. A malicious actor could inject instructions into these data sources to bias the agent's assessment or trick it into proposing the removal of important (but non-security-critical) components.
  • Ingestion points: Usage logs, git history, tickets, surveys, and stakeholder confirmation, as defined in SKILL.md (Trigger Guidance) and reference/evaluation-criteria.md.
  • Boundary markers: The skill instructions in SKILL.md include explicit "Never" rules regarding safety-critical code (auth, encryption, input validation) and "Ask First" gates for public APIs or data-integrity targets.
  • Capability inventory: The skill is strictly advisory and read-only. SKILL.md explicitly forbids the agent from editing code, documents, or executing deletion work directly, routing these tasks to other agents like Sweep or Zen.
  • Sanitization: No specific data sanitization is mentioned; the skill relies on evidence-based quantification (Cost-of-Keeping score) and human-in-the-loop routing for its final recommendations.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 01:49 PM
Security Audit — agent-trust-hub — void