evolution-reporter

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [Indirect Prompt Injection] (LOW): The skill provides a mechanism to aggregate data from the local environment into reports, which creates a surface where the agent could potentially ingest and follow instructions embedded within the data it is processing.
  • Ingestion points: The skill uses tools such as Read, Glob, and Grep to ingest data from the ecosystem (referenced in SKILL.md).
  • Boundary markers: The provided report templates in SKILL.md do not include specific delimiters or warnings to the LLM to ignore instructions found within the data.
  • Capability inventory: The skill allows for the use of powerful tools including Bash, Write, Edit, and WebFetch.
  • Sanitization: There is no logic provided to sanitize or validate the content of the files being read before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:30 PM