referral-request

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's operations are limited to reading and writing local files and interacting with local MCP blackboard tools for workflow management.
  • [DATA_EXPOSURE]: The skill accesses personal contact information and interaction history stored in search/context/connection-tracker.yaml and role data in search/pipeline/open-roles.yaml. This access is necessary for generating personalized messages and the data is not transmitted to any external services.
  • [COMMAND_EXECUTION]: While the Bash tool is enabled in the allowed-tools configuration, the skill instructions do not utilize it for executing shell commands, focusing instead on file operations and specific MCP tools.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an ingestion surface by reading external YAML files (connection-tracker.yaml, open-roles.yaml) without explicit boundary markers or sanitization. However, since these files are part of the local search/ context typically managed by the user's own agent environment, the risk is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 05:36 AM
Security Audit — agent-trust-hub — referral-request