guard

Pass

Audited by Gen Agent Trust Hub on Mar 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, command execution, or unauthorized network activity were identified within the skill's instructions.
  • [PROMPT_INJECTION]: The instructions do not contain patterns typical of prompt injection, jailbreaking, or safety bypass attempts.
  • [DATA_EXFILTRATION]: The skill does not access sensitive credential files (e.g., .env, .ssh) or perform network requests to external domains.
  • [INDIRECT_PROMPT_INJECTION]: This category identifies the attack surface for external data ingestion.
  • Ingestion points: The [path prefix] argument is accepted as user input and written to a state file.
  • Boundary markers: None provided in the instruction set to delimit the input.
  • Capability inventory: Uses the Write tool to manage a local file (production/session-state/safety-mode.md).
  • Sanitization: No explicit sanitization or validation logic is defined for the input path string before it is persisted.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 28, 2026, 12:11 PM
Security Audit — agent-trust-hub — guard