helio-findings

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns or security risks were detected in the skill instructions or reference material. The content is purely instructional and follows established research documentation practices.
  • [PROMPT_INJECTION]: The skill documents the processing of user-generated research data (findings, comments, and responses), which constitutes an indirect prompt injection surface.
  • Ingestion points: Helio study data, including rich text findings and participant responses, as described in SKILL.md and reference.md.
  • Boundary markers: The instructions do not explicitly provide delimiters or warnings to ignore potential instructions embedded within the ingested research data.
  • Capability inventory: The skill is instructional and intended for use with tools that manage Helio findings, project data, and sharing URLs.
  • Sanitization: The reference.md file explicitly notes that the Helio platform sanitizes HTML content within findings.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 11:58 PM
Security Audit — agent-trust-hub — helio-findings