core-actionbook

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [SAFE]: The skill contains no executable scripts, binaries, or command-line instructions. It functions solely as a documentation and metadata provider for MCP tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill establishes a surface for processing untrusted data through the query and id parameters of the search_actions and get_action_by_id tools. 1. Ingestion points: query and id parameters in SKILL.md. 2. Boundary markers: None defined in this manifest. 3. Capability inventory: No implementation scripts are present in the skill folder; the manifest describes browser automation capabilities (click, type, extract). 4. Sanitization: Not specified in the metadata.
  • [SAFE]: The execution environment is restricted by frontmatter settings (user-invocable: false and disable-model-invocation: true) and the agent policy (allow_implicit_invocation: false), ensuring the skill is only used in authorized internal research workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:57 AM
Security Audit — agent-trust-hub — core-actionbook