application-optimiser
Pass
Audited by Gen Agent Trust Hub on Apr 19, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection as it processes untrusted data from the web using
WebSearchandWebFetch(detailed inreferences/company-research.md). Adversarial instructions on external sites could attempt to mislead the agent; however, the skill significantly reduces this risk through a mandatory 'Traceability Check' and 'Hallucination Red Flag Scan' defined inreferences/reflect-validate.mdandreferences/verified-content-guardrails.md. These mechanisms ensure that only user-confirmed facts are included in the final output, effectively ignoring unverified external instructions. - [DATA_EXFILTRATION]: The skill accesses sensitive personal files such as
master-facts.mdandcareer-helper-preferences.mdwithin the working directory. This access is limited to the skill's primary function of document personalization and accessibility adjustment. Analysis of the search and fetch patterns shows that personal history and metrics are kept local to the session and are not exfiltrated to external domains during the research phases.
Audit Metadata