glare-review-rubric

Pass

Audited by Gen Agent Trust Hub on May 14, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is composed of static instructional content and reference documentation for analyzing transcripts. It performs no high-risk operations.\n- [NO_CODE]: The skill does not include or reference any scripts, binaries, or package dependencies for execution.\n- [PROMPT_INJECTION]: The skill processes untrusted user-provided transcripts, which is a surface for indirect prompt injection. 1. Ingestion points: Call transcripts are processed as the primary input (SKILL.md). 2. Boundary markers: The instructions mandate that all scores must be anchored to verbatim quotes from the transcript, which encourages the agent to treat the text as data rather than instructions. 3. Capability inventory: Analysis of the skill files confirms no access to network tools, file system writing, or shell execution. 4. Sanitization: No explicit input sanitization or filtering is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
May 14, 2026, 07:13 PM
Security Audit — agent-trust-hub — glare-review-rubric