mutual-action-plan-builder
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of markdown instructions and documentation. No tools, scripts, or executable code are present in the provided skill content.
- [INDIRECT_PROMPT_INJECTION]: The skill describes a process for ingesting external, untrusted buyer-provided data (SKILL.md). While this creates an ingestion surface, the skill lacks any capabilities to execute code, perform network operations, or write to the file system. It recommends the use of placeholders like [CONFIRM WITH BUYER] and [TBD] for unknown information, which provides basic boundary markers within the generated content. No sanitization is specified for the input data, but the overall threat is negligible due to the absence of exploitable tools or capabilities.
Audit Metadata