salim
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATIONEXTERNAL_DOWNLOADS
Full Analysis
- [PROMPT_INJECTION]: The agent is exposed to indirect prompt injection risks as it is designed to ingest and process content from external, untrusted sources within a user's workspace.\n
- Ingestion points: The skill reads data from the user's Notion workspace, GitHub repositories, and collaborative documents within the Proof system (AGENTS.md).\n
- Boundary markers: The instructions do not define explicit delimiters or instructions to ignore potential commands embedded within retrieved user data.\n
- Capability inventory: The agent has the capability to read and write to the Proof document system and has read access to Notion and GitHub workspaces (AGENTS.md).\n
- Sanitization: No documented evidence of validation, escaping, or filtering of external content was found.\n- [DATA_EXFILTRATION]: The skill operates with read access to the user's private Notion and GitHub environments (AGENTS.md). The skill also contains personal contact information for the studio lead (karanmjpinto@gmail.com) and references to private Notion workspace paths (MEMORY.md).\n- [EXTERNAL_DOWNLOADS]: The skill documentation includes instructions to install plugins from the authoring organization's official GitHub repository (github.com/The-Utopia-Studio/skills). These are recognized as vendor-owned resources.
Audit Metadata