quantity-surveyor
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided project data such as scope definitions and contractor quotes. 1. Ingestion points: User queries for estimates, claims, and change orders (SKILL.md). 2. Boundary markers: Absent. 3. Capability inventory: No tools, subprocess calls, or network operations are defined in the skill. 4. Sanitization: Absent. While an attack surface exists, the lack of capabilities prevents exploitation.
- [SAFE]: The skill configuration and references consist entirely of informational text and professional templates. No evidence of prompt injection, data exfiltration, or malicious persistence was found.
Audit Metadata