source-to-skill-distiller

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external content (documents, transcripts, codebases), creating a potential indirect prompt injection vulnerability.\n
  • Ingestion points: Ingests notes, documents, PDFs, transcripts, videos, courses, repositories, workflows, and chat logs (SKILL.md, description).\n
  • Boundary markers: The workflow emphasizes logical boundaries (Workflow step 1, Rule source-skill-1), but does not mandate technical delimiters to isolate external content from instruction context.\n
  • Capability inventory: The agent can author and patch repository files and execute local validation scripts (Workflow step 8, references/source-to-skill-patterns.md).\n
  • Sanitization: No specific sanitization or escaping mechanisms for external content are defined beyond original synthesis.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 04:07 AM
Security Audit — agent-trust-hub — source-to-skill-distiller