security-awareness

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No malicious instructions or bypass attempts were detected. The skill content focuses on reinforcing security boundaries and ensuring user safety.\n- [DATA_EXFILTRATION]: No hardcoded credentials or exfiltration patterns were found. The skill explicitly provides instructions on how to identify and protect sensitive data like API keys and tokens, preventing their exposure in persistent channels.\n- [OBFUSCATION]: No hidden text, encoded strings, or homoglyph attacks were detected in the skill content. All instructions are provided in clear, plain language.\n- [REMOTE_CODE_EXECUTION]: The skill does not download or execute external scripts or packages. It relies on a set of standard tools for reading and fetching data under strict analytical oversight.\n- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process untrusted data such as emails and URLs, it includes mandatory instructions for the agent to perform character-by-character domain verification and social engineering analysis before acting, which serves as a mitigation for potential injection attacks in external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 09:45 PM
Security Audit — agent-trust-hub — security-awareness