skill-vetter

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to analyze untrusted content from other skill files, creating an ingestion point for potential instructions. However, the lack of powerful permissions significantly mitigates the risk. 1. Ingestion points: Processes external SKILL.md content via file-read access. 2. Boundary markers: No explicit delimiters are specified to isolate the content being audited from the agent's core instructions. 3. Capability inventory: The skill is restricted to file-read access only. No file-write, network, or shell permissions are requested. 4. Sanitization: No explicit sanitization or escaping of the input content is defined.
  • [PROMPT_INJECTION]: The skill includes phrases like 'ignore previous instructions' within a warning list. These are examples for the agent to identify as red flags in other content and do not serve as directive instructions to the agent itself.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 02:13 AM
Security Audit — agent-trust-hub — skill-vetter