biz-lean-six-sigma
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions do not contain any commands designed to bypass safety filters, override system prompts, or extract internal instructions. The content is strictly focused on business process improvement.
- [DATA_EXPOSURE_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or network operations were found in the skill or its reference files.
- [OBFUSCATION]: A scan for hidden content, including Base64 encoding, zero-width characters, and homoglyphs, returned no findings. All text is legible and relates directly to the stated purpose.
- [UNVERIFIABLE_DEPENDENCIES_RCE]: The skill does not include any dependency files (such as package.json or requirements.txt) and does not attempt to download or execute external code.
- [PRIVILEGE_ESCALATION]: There are no commands that attempt to elevate permissions or modify system configurations.
- [PERSISTENCE]: No attempts to create scheduled tasks, modify shell profiles, or establish persistence were detected.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided business scenarios, it lacks any functional tools or capabilities (such as network access or file writing) that could be exploited via indirect injection. The risk is negligible.
- [DYNAMIC_CONTEXT_INJECTION]: No use of the dynamic command execution syntax (!
command) was found in the SKILL.md file. - [DYNAMIC_EXECUTION]: The skill consists entirely of markdown documentation and does not generate or execute code at runtime.
Audit Metadata