reporting
Pass
Audited by Gen Agent Trust Hub on Apr 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill follows security best practices for reporting by emphasizing live data over stale memory and requiring explicit source attribution.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it is designed to ingest and process untrusted external data.
- Ingestion points: Data is fetched from external systems including social media mentions, customer signals, and email content (receipts/invoices) as described in SKILL.md.
- Boundary markers: The instructions lack specific delimiters or instructions to ignore potential commands embedded within the retrieved external data.
- Capability inventory: The skill has significant capabilities, including executing CLI commands (git, gh) and interacting with various APIs and MCP tools.
- Sanitization: No explicit sanitization or validation steps are defined for the content extracted from external unstructured sources.
Audit Metadata