actor-profile

Pass

Audited by Gen Agent Trust Hub on May 5, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill facilitates the analysis of external data sources (code, transcripts, and business documents) to generate actor profiles, which creates a surface for indirect prompt injection if malicious instructions are present in those sources.\n
  • Ingestion points: The skill explicitly mentions building profiles from 'Mixed Inputs' including code, transcripts, and business documents.\n
  • Boundary markers: Absent; there are no instructions to the agent to ignore embedded commands or distinguish between the skill's instructions and the content of the data being analyzed.\n
  • Capability inventory: The skill directs the agent to write generated documentation to the 'docs/service-design/' directory.\n
  • Sanitization: Absent; the instructions do not include validation or sanitization steps for content extracted from external sources.\n- [NO_CODE]: This skill is entirely instructional and does not provide any executable scripts, binaries, or automated tool configurations.
Audit Metadata
Risk Level
SAFE
Analyzed
May 5, 2026, 08:53 PM
Security Audit — agent-trust-hub — actor-profile