skills/xsavikx/okf-skills/okf-lint/Gen Agent Trust Hub

okf-lint

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the file system when validating OKF bundles. * Ingestion points: The ScanBundle function in main.go reads files from the directory path provided to the --bundle flag. * Boundary markers: The skill outputs validation results in text or JSON format but does not implement boundary markers or instructions to prevent an AI agent from misinterpreting content within the bundle concepts as commands. * Capability inventory: The tool's capabilities are limited to reading local files within the specified bundle and writing validation reports to standard output. No network or destructive file system capabilities were found. * Sanitization: The tool performs spec conformance validation but does not sanitize textual content for potential prompt injection strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 08:04 AM
Security Audit — agent-trust-hub — okf-lint