wait-what
Pass
Audited by Gen Agent Trust Hub on Sep 1, 2026
Risk Level: SAFENO_CODEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill contains no executable code, scripts, or external network operations. The content is limited to instructional text and configuration metadata.
- [NO_CODE]: No software dependencies or scripts are included or installed by this skill.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a data ingestion surface by instructing the agent to process content from an external file (CONTEXT.md). This finding is assessed as safe because the skill lacks any exploitable capabilities, such as network access or file system write permissions, and tool invocation is explicitly disabled in the metadata. 1. Ingestion points: The CONTEXT.md file referenced in SKILL.md. 2. Boundary markers: None identified. 3. Capability inventory: None (model tool invocation is disabled). 4. Sanitization: None identified.
Audit Metadata