quality-audit

Pass

Audited by Gen Agent Trust Hub on Mar 29, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [SAFE]: The skill serves as a documentation and framework resource for skill quality assurance. No malicious code or hidden instructions were detected within the skill content.\n- [PROMPT_INJECTION]: The skill defines a workflow for evaluating untrusted external data (other skills), creating a theoretical surface for indirect prompt injection. 1. Ingestion points: Assessment involves reading the SKILL.md files of external skills. 2. Boundary markers: The framework relies on structured rubric scores rather than direct prompt interpolation of audited content. 3. Capability inventory: Mentions the cortex CLI tool for structural validation. 4. Sanitization: Evaluation is based on manual scoring dimensions which inherently requires human-in-the-loop validation of content correctness.\n- [COMMAND_EXECUTION]: Provides documentation and example command-line patterns for the cortex CLI tool, which is a platform-associated utility provided by the vendor.\n- [EXTERNAL_DOWNLOADS]: Includes documentation for a GitHub Actions workflow that installs the cortex package from a package registry as part of a standard development setup.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 29, 2026, 05:13 PM