developer-visibility

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOWPROMPT_INJECTION
Full Analysis
  • Prompt Injection (SAFE): No instructions attempting to override agent behavior or bypass safety filters were detected in the instructional content.- Data Exposure & Exfiltration (SAFE): No hardcoded credentials, sensitive file paths, or unauthorized exfiltration commands were found.- Obfuscation (SAFE): Analysis of the markdown content for Base64, zero-width characters, and homoglyphs returned no findings.- Indirect Prompt Injection (LOW): The skill defines WebFetch and WebSearch as allowed tools for the agent. Evidence: 1) Ingestion Points: Tools for web access; 2) Boundary Markers: Absent; 3) Capability Inventory: Tools are limited to read-only operations (Read, Glob, Grep, WebFetch, WebSearch); 4) Sanitization: Absent. This creates a Tier LOW surface where external web content could influence agent reasoning without allowing for external write or execute side effects.- Unverifiable Dependencies (SAFE): The skill contains no code, script downloads, or package dependency files.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 01:21 AM