permission-auditor

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external data, specifically the descriptions and permission configurations of other skills. This creates a potential surface where a malicious skill description could attempt to influence the analyst's output or recommendations.
  • Ingestion points: User-supplied skill metadata and permission sets provided during the audit workflow.
  • Boundary markers: The instructions lack explicit delimiters or 'ignore' directives to separate the skill's analytical logic from the untrusted data being analyzed.
  • Capability inventory: The skill is highly restricted, requesting only file-read permissions and no network, shell, or file-write access, which prevents any significant exploitation.
  • Sanitization: No explicit validation or sanitization of the input data is defined in the instructions.
  • [SAFE]: The skill's body contains educational descriptions of high-risk file paths (e.g., ~/.ssh/id_rsa, ~/.aws/credentials) and severity levels (e.g., CRITICAL, HIGH). These are used as benign instructional examples to explain security risks to the user and do not represent attempts to access sensitive data or override system behavior.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:43 AM
Security Audit — agent-trust-hub — permission-auditor