network-report-documents
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from network devices and ServiceNow (Indirect Prompt Injection surface). It specifically mitigates risks associated with untrusted text by requiring literal rendering to prevent spreadsheet formula injection. Evidence: 1. Ingestion points: Data is retrieved via
servicenow-change-workflow,fortigate-ops, andpyats. 2. Boundary markers: Explicit instructions prohibit data fabrication and require reporting of missing values. 3. Capability inventory: Writing Word, Excel, PowerPoint, and PDF files viadocument-mcp. 4. Sanitization: The skill identifies device descriptions as untrusted and enforces literal rendering to prevent formula injection in workbooks. - [COMMAND_EXECUTION]: The skill coordinates several external tools for data retrieval and document generation. These operations are consistent with the skill's stated purpose and are scoped to vendor-specific and industry-standard tools like
pyatsanddocument-mcp. - [DATA_EXFILTRATION]: While the skill accesses sensitive network configuration data, it defines clear boundaries that separate document creation from delivery actions, delegating transmission to separate authorized skills.
Audit Metadata