app-rejection-recovery

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is entirely instructional and consultative. It does not contain any scripts, command-line executions, network requests, or attempts to access sensitive system files.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a theoretical attack surface because it asks the user to provide external content (rejection messages). However, since the skill has no identified capabilities for file writing, network exfiltration, or command execution, this surface is not exploitable. 1. Ingestion points: The 'Initial Assessment' section in SKILL.md requests the full rejection message from the user. 2. Boundary markers: No explicit delimiters or instructions are provided to the agent to treat this input as potentially untrusted data. 3. Capability inventory: None identified across the skill body. 4. Sanitization: The skill does not implement any validation or sanitization of the provided rejection text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:04 PM
Security Audit — agent-trust-hub — app-rejection-recovery