skills/udecode/dotai/unslop/Gen Agent Trust Hub

unslop

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use a bundled JavaScript script (scripts/audit-prose.mjs) to audit prose. The script runs locally via Node.js and uses standard library modules for file system access without performing network requests or accessing sensitive system configuration files.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted prose files, creating an indirect prompt injection surface. \n
  • Ingestion points: Prose text is read from files during directory audits and editing tasks. \n
  • Boundary markers: The skill includes a 'Core contract' and reference documentation explicitly instructing the agent to protect non-prose content such as code, data, and identifiers. \n
  • Capability inventory: The agent is granted capabilities to read and modify local prose files. \n
  • Sanitization: The provided audit script detects and flags AI-writing artifacts and reasoning leaks, which serves as a detection layer for injection-related content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 11:47 AM
Security Audit — agent-trust-hub — unslop