skills/tranz007/ux-skills/decision/Gen Agent Trust Hub

decision

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill directs the agent to analyze external data from sources such as issue and PR history, research, and project documentation. This creates a surface for indirect prompt injection where instructions embedded in these external files could potentially influence the agent's behavior.
  • Ingestion points: External artifacts like decision records, research, requirements, issue/PR history, and design-system documentation as specified in SKILL.md.
  • Boundary markers: The skill does not provide specific instructions to delimit or ignore instructions found within these external sources.
  • Capability inventory: The skill does not define or use high-risk tools such as network access or arbitrary command execution.
  • Sanitization: No sanitization or validation of the ingested external content is mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 02:55 AM
Security Audit — agent-trust-hub — decision