skill-audit

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill text contains phrases such as "ignore previous instructions" and "you are now..." within its documentation and examples. While these are presented as targets for detection rather than commands for the agent, their presence in the instruction set constitutes a minor prompt injection risk.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface.
  • Ingestion points: The skill is designed to process untrusted data by instructing the agent to "Read every referenced script" and perform "Pattern detection in SKILL.md" of third-party repositories.
  • Boundary markers: The instructions do not specify the use of delimiters or provide "ignore embedded instructions" warnings when evaluating external skill content.
  • Capability inventory: The skill uses standard agent file-read and evaluation tools; no dangerous subprocess or network capabilities are explicitly requested by the skill itself.
  • Sanitization: No sanitization or filtering of the external data being analyzed is described in the 6-phase process.
  • [SAFE]: The skill does not request the installation of external packages, perform network exfiltration, or access sensitive user credentials. Its operations are restricted to evaluating the content of other skill files as part of a security review.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 10:05 AM
Security Audit — agent-trust-hub — skill-audit