nip85-trusted-assertions

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is entirely informational, serving as an operative definition and documentation for handling NIP-85 Nostr events within a Kotlin-based project.
  • [SAFE]: No hardcoded credentials, API keys, or sensitive environment variable paths were detected. Placeholders are used appropriately for example purposes.
  • [SAFE]: There are no attempts at prompt injection, obfuscation, or persistence. The content is clear and follows standard documentation practices.
  • [SAFE]: While the skill describes an attack surface for indirect prompt injection (parsing external Nostr events), it correctly identifies validation concerns (e.g., unclamped values, missing range checks) and instructs developers to implement consumer-side defenses.
  • [SAFE]: The external URLs mentioned (e.g., brainstorm.world) are standard Nostr relays relevant to the protocol being described and are not used for exfiltration or malicious downloads within the context of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 07:48 PM
Security Audit — agent-trust-hub — nip85-trusted-assertions