to-questionnaire
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates as a document generation tool with no identified security risks. It follows a structured template for writing local Markdown files and does not perform network operations, execute code, or access sensitive system areas.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by ingesting user-provided descriptions and role information to generate a Markdown questionnaire. This behavior is inherent to its primary purpose as a document creation tool.
- Ingestion points: User input provided in response to the interview steps in
SKILL.md. - Boundary markers: The agent is instructed to follow a specific
<questionnaire-template>for the output file. - Capability inventory: The skill is capable of writing local Markdown files (
to-questionnaire-<slug>.md). - Sanitization: No explicit sanitization or filtering of user input is defined before writing to the output file.
Audit Metadata