account-recovery

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown-based documentation and architectural guidance. It does not include any scripts, executable commands, or external dependencies.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or obfuscation was found. The instructions are focused on guiding the agent to assess account recovery procedures.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided descriptions of authentication flows for review. While this constitutes an attack surface where a user could provide malicious input to influence agent behavior, the skill lacks tool-based capabilities (such as file writing or network requests) that would make such an injection exploitable. In its current form, the risk is negligible.
  • Ingestion points: User-provided recovery flow descriptions (SKILL.md)
  • Boundary markers: None present
  • Capability inventory: No tools or subprocess calls identified
  • Sanitization: Not applicable as no processing or interpolation occurs
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 03:31 AM
Security Audit — agent-trust-hub — account-recovery