glare-review-ground

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional Markdown content and does not contain any executable scripts, binary files, or automated tool configurations.
  • [SAFE]: No network operations, file system access, or credential usage were detected in the instructions or reference materials.
  • [PROMPT_INJECTION]: The skill is designed to analyze untrusted data in the form of meeting transcripts to identify design signals and score the review process. This represents a surface for indirect prompt injection where malicious instructions could be embedded in the transcript text.
  • Ingestion points: The skill analyzes transcripts as mentioned in point 5 of SKILL.md and the 'What to listen for' section of reference.md.
  • Boundary markers: There are no explicit delimiters or instructions to ignore potential commands within the transcript data.
  • Capability inventory: No tools, subprocesses, or network capabilities are requested or defined in the skill metadata or body.
  • Sanitization: There is no evidence of transcript data sanitization or validation logic.
  • Severity Assessment: Given the total lack of external capabilities or sensitive tool access, this surface represents a negligible security risk.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:13 PM
Security Audit — agent-trust-hub — glare-review-ground