verify-then-advise
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [SAFE]: The skill consists of instructional guidelines for fact-checking and does not contain executable code, scripts, or dangerous tool definitions. The instructions focus on improving the accuracy of recommendations by verifying model knowledge against current external sources.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes an attack surface by directing the agent to ingest external data. 1. Ingestion points: Vendor registries, job postings, and analyst reports mentioned throughout SKILL.md. 2. Boundary markers: The skill does not define specific prompt delimiters for external content. 3. Capability inventory: No scripts, subprocess calls, or file-writing tools are included in the skill body. 4. Sanitization: The skill mandates a framework for manual corroboration and evidence grading to mitigate reliance on potentially biased or malicious external data.
- [EXTERNAL_DOWNLOADS]: The documentation references official Microsoft certification retirement registries and study guides. These target a well-known service for legitimate information gathering and are documented neutrally as they do not escalate the security risk.
Audit Metadata