attack-tree-construction
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No security issues were detected. The skill provides data structures and logic for threat modeling without requesting dangerous permissions or performing risky operations.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process user-provided threat descriptions to generate visualizations and analysis. While this represents a surface for indirect prompt injection, the skill lacks the capabilities (network, file system, or command execution) required to exploit such an injection.\n
- Ingestion points: User-provided threat scenarios (SKILL.md).\n
- Boundary markers: None present.\n
- Capability inventory: None (no subprocess calls, exec/eval, file-write, or network operations detected in references/details.md or SKILL.md).\n
- Sanitization: None present.
Audit Metadata