duck-risk
Pass
Audited by Gen Agent Trust Hub on Aug 18, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: No evidence of instructions designed to bypass safety filters or override agent constraints. The skill includes a dedicated 'Shared Guardrails' file that explicitly reinforces security controls and user ownership of decisions.
- [DATA_EXFILTRATION]: No network operations (e.g., curl, fetch) or hardcoded credentials were detected. The skill does not access sensitive local file paths.
- [REMOTE_CODE_EXECUTION]: The skill consists entirely of Markdown instructions and does not download or execute any external scripts or packages.
- [OBFUSCATION]: No hidden characters, Base64 encoding, or homoglyphs were found in the text or metadata.
- [INDIRECT_PROMPT_INJECTION]: While the skill processes user-provided proposals (untrusted data), it lacks the capabilities (file writes, network sends, or code execution) necessary to facilitate an attack. It functions as a text analyzer only.
Audit Metadata