ask-user-question
Pass
Audited by Gen Agent Trust Hub on Feb 16, 2026
Risk Level: LOW
Full Analysis
- [SAFE] (SAFE): The file consists of documentation for an MCP tool and does not contain malicious code, instructions, or obfuscation.
- [Indirect Prompt Injection] (INFO): The tool captures user input via the 'Other' option or selection labels, which enters the agent context. However, the skill has no side-effect capabilities (no file writes, network calls, or code execution) and lacks the ability to execute the ingested data, resulting in a negligible risk profile. The inclusion of confirmation prompts is a recommended security pattern.
Audit Metadata