m09-domain
Pass
Audited by Gen Agent Trust Hub on Feb 15, 2026
Risk Level: LOW
Full Analysis
- Prompt Injection (SAFE): No patterns of instruction override, safety bypass, or role-play jailbreaks were detected. The 'CRITICAL' keyword in the description is used for framework categorization rather than as a malicious override marker.
- Data Exposure & Exfiltration (SAFE): There are no attempts to access sensitive system files, environment variables, or hardcoded credentials. No network operations or external data transfer mechanisms are present.
- Obfuscation (SAFE): The content is clear and human-readable. No Base64, zero-width characters, homoglyphs, or encoded payloads were identified.
- Unverifiable Dependencies & Remote Code Execution (SAFE): The skill does not specify external package dependencies (Python/Node.js) or attempt to execute remote scripts or dynamic code.
- Indirect Prompt Injection (INFO): The skill acts as a logic template for processing user design requests. It lacks side-effect capabilities like file system writing or network requests, meaning it only influences the agent's internal reasoning and textual output.
- Privilege Escalation & Persistence (SAFE): No commands related to administrative access, permission changes, or system persistence (crontab, startup scripts) were found.
Audit Metadata