core-actionbook
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [SAFE]: The skill contains no executable scripts, binaries, or command-line instructions. It functions solely as a documentation and metadata provider for MCP tools.
- [INDIRECT_PROMPT_INJECTION]: The skill establishes a surface for processing untrusted data through the
queryandidparameters of thesearch_actionsandget_action_by_idtools. 1. Ingestion points:queryandidparameters inSKILL.md. 2. Boundary markers: None defined in this manifest. 3. Capability inventory: No implementation scripts are present in the skill folder; the manifest describes browser automation capabilities (click, type, extract). 4. Sanitization: Not specified in the metadata. - [SAFE]: The execution environment is restricted by frontmatter settings (
user-invocable: falseanddisable-model-invocation: true) and the agent policy (allow_implicit_invocation: false), ensuring the skill is only used in authorized internal research workflows.
Audit Metadata