guard
Pass
Audited by Gen Agent Trust Hub on Mar 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns, command execution, or unauthorized network activity were identified within the skill's instructions.
- [PROMPT_INJECTION]: The instructions do not contain patterns typical of prompt injection, jailbreaking, or safety bypass attempts.
- [DATA_EXFILTRATION]: The skill does not access sensitive credential files (e.g., .env, .ssh) or perform network requests to external domains.
- [INDIRECT_PROMPT_INJECTION]: This category identifies the attack surface for external data ingestion.
- Ingestion points: The
[path prefix]argument is accepted as user input and written to a state file. - Boundary markers: None provided in the instruction set to delimit the input.
- Capability inventory: Uses the
Writetool to manage a local file (production/session-state/safety-mode.md). - Sanitization: No explicit sanitization or validation logic is defined for the input path string before it is persisted.
Audit Metadata