biz-lean-six-sigma

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill instructions do not contain any commands designed to bypass safety filters, override system prompts, or extract internal instructions. The content is strictly focused on business process improvement.
  • [DATA_EXPOSURE_EXFILTRATION]: No sensitive file paths, hardcoded credentials, or network operations were found in the skill or its reference files.
  • [OBFUSCATION]: A scan for hidden content, including Base64 encoding, zero-width characters, and homoglyphs, returned no findings. All text is legible and relates directly to the stated purpose.
  • [UNVERIFIABLE_DEPENDENCIES_RCE]: The skill does not include any dependency files (such as package.json or requirements.txt) and does not attempt to download or execute external code.
  • [PRIVILEGE_ESCALATION]: There are no commands that attempt to elevate permissions or modify system configurations.
  • [PERSISTENCE]: No attempts to create scheduled tasks, modify shell profiles, or establish persistence were detected.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided business scenarios, it lacks any functional tools or capabilities (such as network access or file writing) that could be exploited via indirect injection. The risk is negligible.
  • [DYNAMIC_CONTEXT_INJECTION]: No use of the dynamic command execution syntax (!command) was found in the SKILL.md file.
  • [DYNAMIC_EXECUTION]: The skill consists entirely of markdown documentation and does not generate or execute code at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 02:05 PM
Security Audit — agent-trust-hub — biz-lean-six-sigma