skills/validkeys/sherpy/sherpy-flow/Gen Agent Trust Hub

sherpy-flow

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (an initial requirements document) during Step 1 of the workflow.
  • Ingestion points: Processes any .md, .txt, or .docx file found in the project directory as an 'initial requirements document' for Gap Analysis (SKILL.md).
  • Boundary markers: There are no instructions to use delimiters or 'ignore embedded instructions' warnings when reading the content of the requirements document.
  • Capability inventory: The skill has the capability to scan directories, create folders, write files, and invoke other specialized skills based on the content of the documents.
  • Sanitization: No sanitization or validation of the document content is performed before it is passed to the analysis skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 03:59 PM
Security Audit — agent-trust-hub — sherpy-flow