vulnerability-triage-brocards
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted vulnerability reports, which constitutes an indirect prompt injection surface. However, the risk is minimal because the skill does not possess any exploitable capabilities such as network requests, file writing, or command execution. The triage workflow is purely analytical and focuses on documentation and logical filtering. (Ingestion points: External vulnerability reports; Boundary markers: Uses a structured triage summary output format; Capability inventory: No tool usage or subprocess execution detected; Sanitization: Qualitative logic-based filtering).
- [SAFE]: No malicious patterns, obfuscation, or dangerous execution capabilities were identified. The skill defines a defensive triage methodology and references legitimate security research and official CVE databases.
Audit Metadata