competition-queue-worker-drift
Pass
Audited by Gen Agent Trust Hub on Jun 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a downstream instructional component for sandbox orchestration and does not contain independent executable code or define new tool permissions.
- [DATA_EXFILTRATION]: While the skill instructions describe tracing credentials and environment variables within a sandbox to identify configuration drift, there are no hardcoded secrets, network exfiltration commands, or unauthorized data access patterns.
- [PROMPT_INJECTION]: The skill identifies an attack surface for indirect prompt injection as it is designed to ingest and analyze untrusted data from queue payloads. Ingestion points: Queue payloads, task IDs, and worker process metadata described in SKILL.md and references/queue-worker-drift.md; Boundary markers: The instructions do not specify explicit delimiters or isolation commands for processed payloads; Capability inventory: No file-write, network-send, or shell-execution capabilities are defined in the analyzed files; Sanitization: No input validation or escaping mechanisms are provided for external payload content.
Audit Metadata