lens
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests user technical inquiries and code, which is a potential surface for indirect injection. The risk is addressed by strict formatting rules and the absence of any functional tools or system access.
- Ingestion points: User inquiries and code snippets (SKILL.md).
- Boundary markers: Explicit instructions to preserve context and ignore scope-mutating tangents.
- Capability inventory: Read-only operation; no file creation, network access, or shell commands.
- Sanitization: Forced adherence to a 35-line markdown template.
- [NO_CODE]: The skill consists entirely of markdown instructions and does not include any executable scripts or binary files.
Audit Metadata