network-report-documents

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted data from network devices and ServiceNow (Indirect Prompt Injection surface). It specifically mitigates risks associated with untrusted text by requiring literal rendering to prevent spreadsheet formula injection. Evidence: 1. Ingestion points: Data is retrieved via servicenow-change-workflow, fortigate-ops, and pyats. 2. Boundary markers: Explicit instructions prohibit data fabrication and require reporting of missing values. 3. Capability inventory: Writing Word, Excel, PowerPoint, and PDF files via document-mcp. 4. Sanitization: The skill identifies device descriptions as untrusted and enforces literal rendering to prevent formula injection in workbooks.
  • [COMMAND_EXECUTION]: The skill coordinates several external tools for data retrieval and document generation. These operations are consistent with the skill's stated purpose and are scoped to vendor-specific and industry-standard tools like pyats and document-mcp.
  • [DATA_EXFILTRATION]: While the skill accesses sensitive network configuration data, it defines clear boundaries that separate document creation from delivery actions, delegating transmission to separate authorized skills.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:47 AM
Security Audit — agent-trust-hub — network-report-documents