uipath-project-knowledge-base

Pass

Audited by Gen Agent Trust Hub on Jul 31, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns, prompt injections, or obfuscation techniques were detected in the skill instructions or metadata.
  • [DATA_EXFILTRATION]: No network access or sensitive file reading commands were identified. The skill includes a guardrail stating 'Do not put credentials, personal data, or unrestricted production records in the knowledge base.'
  • [REMOTE_CODE_EXECUTION]: The skill does not contain any code, package dependencies, or instructions for downloading and executing remote scripts.
  • [PROMPT_INJECTION]: The skill performs ingestion of external project data which presents a theoretical surface for indirect prompt injection, but the lack of executable capabilities makes this a low-risk finding.
  • Ingestion points: SKILL.md references inventorying existing Markdown, SDDs, ADRs, and research notes.
  • Boundary markers: Absent.
  • Capability inventory: The skill only produces Markdown text and does not use any tools or shell commands.
  • Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 31, 2026, 04:38 PM
Security Audit — agent-trust-hub — uipath-project-knowledge-base