network-watcher
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze third-party skill files (SKILL.md), which creates a surface for indirect prompt injection where a malicious skill could attempt to influence the agent's security verdict through embedded instructions.
- Ingestion points: The agent is instructed to read and scan the content of third-party SKILL.md files during pre-install and runtime audit phases.
- Boundary markers: The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings when the agent processes these external files.
- Capability inventory: The skill only requests 'file-read' permissions; it lacks 'network', 'shell', and 'file-write' capabilities, which effectively mitigates the potential harm from any successful prompt injection.
- Sanitization: There are no explicit instructions for the agent to sanitize, escape, or validate the content extracted from external files before performing the audit.
Audit Metadata