business-intelligence

Pass

Audited by Gen Agent Trust Hub on Sep 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows security best practices. All scripts and instructions are well-defined and purpose-built for analytics tasks.
  • [COMMAND_EXECUTION]: The skill utilizes local Python scripts (kpi_tracker.py, dashboard_spec_generator.py, metric_validator.py) for data analysis. Technical analysis of these scripts confirms they perform safe JSON/CSV parsing and arithmetic operations. They do not invoke shell commands, spawn subprocesses, or allow for arbitrary command injection.
  • [DATA_EXFILTRATION]: No network operations (e.g., requests, urllib, curl) or exfiltration patterns were detected. The scripts only process local data and output results to the console. No hardcoded credentials or access to sensitive system paths were identified.
  • [DYNAMIC_EXECUTION]: The skill and its associated scripts do not use dangerous functions such as eval(), exec(), or unsafe deserialization techniques. Data is processed using the Python standard library's json and csv modules.
  • [INDIRECT_PROMPT_INJECTION]: The skill has a defined attack surface in the form of local data ingestion (KPI definitions and metrics files). However, the scripts act as a strict logic boundary; the ingested data is used solely for calculation and layout generation, posing no risk to the underlying agent's safety protocols.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 29, 2026, 03:13 AM
Security Audit — agent-trust-hub — business-intelligence