master-mahasi-sayadaw
Pass
Audited by Gen Agent Trust Hub on May 10, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill uses defensive prompts to constrain the agent's behavior, specifically prohibiting the judgment of spiritual attainments (attainment judgment) and the fabrication of quotes. These instructions serve as internal safety guardrails rather than malicious injections.\n- [DATA_EXFILTRATION]: No unauthorized network operations or sensitive data access patterns were found. Referenced external domains (e.g., SuttaCentral.net, mahasi.org.mm) are official and trusted resources within the Buddhist educational context.\n- [REMOTE_CODE_EXECUTION]: No remote code execution or untrusted downloads are present. The skill mentions local auxiliary scripts for citation and querying, but no code for these scripts was provided for analysis, and there are no instructions to download external payloads.\n- [OBFUSCATION]: A thorough review of the text files found no evidence of Base64 encoding, zero-width characters, homoglyphs, or other obfuscation techniques intended to hide malicious instructions or URLs.\n- [COMMAND_EXECUTION]: No dangerous shell commands or privilege escalation attempts were detected. The mentioned script usage is localized and restricted to specific retrieval tasks.
Audit Metadata