to-questionnaire

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill operates as a document generation tool with no identified security risks. It follows a structured template for writing local Markdown files and does not perform network operations, execute code, or access sensitive system areas.
  • [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by ingesting user-provided descriptions and role information to generate a Markdown questionnaire. This behavior is inherent to its primary purpose as a document creation tool.
  • Ingestion points: User input provided in response to the interview steps in SKILL.md.
  • Boundary markers: The agent is instructed to follow a specific <questionnaire-template> for the output file.
  • Capability inventory: The skill is capable of writing local Markdown files (to-questionnaire-<slug>.md).
  • Sanitization: No explicit sanitization or filtering of user input is defined before writing to the output file.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 09:23 PM
Security Audit — agent-trust-hub — to-questionnaire