account-recovery
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of markdown-based documentation and architectural guidance. It does not include any scripts, executable commands, or external dependencies.
- [SAFE]: No evidence of prompt injection, data exfiltration, or obfuscation was found. The instructions are focused on guiding the agent to assess account recovery procedures.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided descriptions of authentication flows for review. While this constitutes an attack surface where a user could provide malicious input to influence agent behavior, the skill lacks tool-based capabilities (such as file writing or network requests) that would make such an injection exploitable. In its current form, the risk is negligible.
- Ingestion points: User-provided recovery flow descriptions (SKILL.md)
- Boundary markers: None present
- Capability inventory: No tools or subprocess calls identified
- Sanitization: Not applicable as no processing or interpolation occurs
Audit Metadata