referral-request
Pass
Audited by Gen Agent Trust Hub on May 1, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill's operations are limited to reading and writing local files and interacting with local MCP blackboard tools for workflow management.
- [DATA_EXPOSURE]: The skill accesses personal contact information and interaction history stored in
search/context/connection-tracker.yamland role data insearch/pipeline/open-roles.yaml. This access is necessary for generating personalized messages and the data is not transmitted to any external services. - [COMMAND_EXECUTION]: While the
Bashtool is enabled in theallowed-toolsconfiguration, the skill instructions do not utilize it for executing shell commands, focusing instead on file operations and specific MCP tools. - [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface by reading external YAML files (
connection-tracker.yaml,open-roles.yaml) without explicit boundary markers or sanitization. However, since these files are part of the localsearch/context typically managed by the user's own agent environment, the risk is negligible.
Audit Metadata