skills/tonone-ai/tonone/lumen-abtest/Gen Agent Trust Hub

lumen-abtest

Pass

Audited by Gen Agent Trust Hub on Jul 1, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill content is focused on legitimate product analysis tasks, providing statistical formulas and logical frameworks for experiment design.
  • [COMMAND_EXECUTION]: The skill instructs the agent to invoke an external command named /atlas-report for generating detailed HTML reports when output exceeds length limits.
  • Evidence: The 'Delivery' section in SKILL.md specifies: 'invoke /atlas-report with the full findings'.
  • [PROMPT_INJECTION]: The skill has a surface for indirect prompt injection as it processes user-provided descriptions of product changes to generate experiment plans.
  • Ingestion points: The agent is prompted to design tests 'Given a change to test' as described in SKILL.md.
  • Boundary markers: The instructions lack explicit boundary markers or 'ignore' instructions for the processed user data.
  • Capability inventory: The skill is authorized to use 'Bash', 'Write', 'Edit', and 'WebFetch' tools according to the allowed-tools frontmatter.
  • Sanitization: No sanitization or escaping mechanisms for the user input are defined in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 1, 2026, 02:47 PM
Security Audit — agent-trust-hub — lumen-abtest