aidlc-session-cost
Pass
Audited by Gen Agent Trust Hub on Oct 4, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is designed for read-only reporting of workflow metrics. No evidence of malicious patterns such as data exfiltration, persistence, or privilege escalation was detected.
- [COMMAND_EXECUTION]: The skill executes a local engine command (
engine runtime summary) to fetch workflow statistics. This is the primary intended function of the skill and uses the platform's native tool invocation mechanism without exposing the agent to unsanitized user input. - [INDIRECT_PROMPT_INJECTION]: The skill processes JSON output from a local command. While this represents a data ingestion point, the risk is minimal as the instructions restrict the agent to verbatim rendering of specific numeric and status fields, providing a limited attack surface.
Audit Metadata