ask-question

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill implements an indirect prompt injection surface through its session persistence feature.
  • Ingestion points: User-provided answers are collected during the interactive Q&A process.
  • Boundary markers: No delimiters are specified to isolate user input within the generated .qa.md file.
  • Capability inventory: The skill utilizes the Write tool for file creation and data appending.
  • Sanitization: No sanitization is performed on user content before it is persisted to the local filesystem. This surface is inherent to the skill's intended purpose of recording a conversation.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:48 PM
Security Audit — agent-trust-hub — ask-question