gift-pack-penetration-analysis

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's instructions, metadata, and localization files were reviewed and no malicious patterns, base64 obfuscation, or hidden commands were found.
  • [COMMAND_EXECUTION]: The skill specifies the use of analytical tools (e.g., 'analysis report', 'analysis dashboard', 'analysis adhoc') to retrieve and process gift pack data. These tool calls are limited to the agent's analytical domain and include instructions for secure parameter handling.
  • [INDIRECT_PROMPT_INJECTION]: As an analytical tool, the skill processes external data which is a potential surface for indirect injection.
  • Ingestion points: Untrusted data enters the context via 'analysis report-data run' and 'analysis adhoc run' output as described in 'SKILL.md'.
  • Boundary markers: The workflow requires the use of structured JSON definitions ('--definition ') for data queries.
  • Capability inventory: The skill uses tools for data retrieval and report management across its workflow stages.
  • Sanitization: The skill includes explicit instructions to use AI-facing event definitions rather than raw query parameters or frontend DTOs, reducing the risk of processing malicious inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 10:17 AM
Security Audit — agent-trust-hub — gift-pack-penetration-analysis