helio-findings
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns or security risks were detected in the skill instructions or reference material. The content is purely instructional and follows established research documentation practices.
- [PROMPT_INJECTION]: The skill documents the processing of user-generated research data (findings, comments, and responses), which constitutes an indirect prompt injection surface.
- Ingestion points: Helio study data, including rich text findings and participant responses, as described in
SKILL.mdandreference.md. - Boundary markers: The instructions do not explicitly provide delimiters or warnings to ignore potential instructions embedded within the ingested research data.
- Capability inventory: The skill is instructional and intended for use with tools that manage Helio findings, project data, and sharing URLs.
- Sanitization: The
reference.mdfile explicitly notes that the Helio platform sanitizes HTML content within findings.
Audit Metadata