m09-domain

Pass

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: LOW
Full Analysis
  • Prompt Injection (SAFE): No patterns of instruction override, safety bypass, or role-play jailbreaks were detected. The 'CRITICAL' keyword in the description is used for framework categorization rather than as a malicious override marker.
  • Data Exposure & Exfiltration (SAFE): There are no attempts to access sensitive system files, environment variables, or hardcoded credentials. No network operations or external data transfer mechanisms are present.
  • Obfuscation (SAFE): The content is clear and human-readable. No Base64, zero-width characters, homoglyphs, or encoded payloads were identified.
  • Unverifiable Dependencies & Remote Code Execution (SAFE): The skill does not specify external package dependencies (Python/Node.js) or attempt to execute remote scripts or dynamic code.
  • Indirect Prompt Injection (INFO): The skill acts as a logic template for processing user design requests. It lacks side-effect capabilities like file system writing or network requests, meaning it only influences the agent's internal reasoning and textual output.
  • Privilege Escalation & Persistence (SAFE): No commands related to administrative access, permission changes, or system persistence (crontab, startup scripts) were found.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 15, 2026, 11:33 PM