reporting

Pass

Audited by Gen Agent Trust Hub on Apr 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices for reporting by emphasizing live data over stale memory and requiring explicit source attribution.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it is designed to ingest and process untrusted external data.
  • Ingestion points: Data is fetched from external systems including social media mentions, customer signals, and email content (receipts/invoices) as described in SKILL.md.
  • Boundary markers: The instructions lack specific delimiters or instructions to ignore potential commands embedded within the retrieved external data.
  • Capability inventory: The skill has significant capabilities, including executing CLI commands (git, gh) and interacting with various APIs and MCP tools.
  • Sanitization: No explicit sanitization or validation steps are defined for the content extracted from external unstructured sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 25, 2026, 09:33 AM
Security Audit — agent-trust-hub — reporting