skills/taecontrol/skills/how/Gen Agent Trust Hub

how

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions are purely cognitive and descriptive, focusing on causal reasoning and clear communication. It does not introduce any scripts, binaries, or network operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze external evidence including code, configuration, and documentation (SKILL.md). While these inputs represent a potential injection surface, the risk is mitigated by clear boundary instructions that restrict the agent to a read-only role and prohibit system modification. No executable capabilities or dangerous tools are present in the skill configuration, and while no specific data sanitization is mentioned, the lack of powerful tools limits the impact of potential injections.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 11:54 PM
Security Audit — agent-trust-hub — how