uipath-discovery-interview

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill does not contain any malicious code, obfuscated commands, or unauthorized data exfiltration patterns. The references to official UiPath resources are legitimate and support the skill's intended use case.
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and process external artifacts and user-provided evidence. 1. Ingestion points: The SKILL.md file instructs the agent to read repository facts directly and collect evidence such as logs, reports, and SOPs. 2. Boundary markers: The instructions lack specific delimiters or directives to ignore instructions embedded within the ingested data. 3. Capability inventory: The skill orchestrates workflows involving other automation discovery and planning tools. 4. Sanitization: No explicit content validation or sanitization of ingested artifacts is defined. This surface is inherent to the skill's primary function and is considered safe.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:39 PM
Security Audit — agent-trust-hub — uipath-discovery-interview