agent-security

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill incorporates a robust 'Prompt Injection Safety Notice' that directs the agent to treat target file content as data rather than instructions. This control specifically targets and mitigates indirect prompt injection by ensuring the agent does not execute commands found in reviewed files.
  • [EXTERNAL_DOWNLOADS]: The skill provides informational links to official OWASP and NIST security documentation and references a GitHub repository for red-team testing. These are presented as user references and do not involve automated script downloads or runtime code execution.
  • [SAFE]: The architecture of the skill follows least-privilege principles by restricting the 'allowed-tools' to read-only operations (Read, Grep, Glob) and aligning all assessment activities with recognized security frameworks like NIST AI RMF 1.0.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 01:06 AM
Security Audit — agent-trust-hub — agent-security