business-analyst

Pass

Audited by Gen Agent Trust Hub on May 1, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill employs dynamic context injection (using the ! syntax) to run shell commands at load time. These commands specifically execute cat on internal project files, such as .production-grade.yaml and .forgewright/settings.md, to incorporate configuration data into the prompt. The commands are hardcoded and do not accept external input.
  • [COMMAND_EXECUTION]: Upon completion of the analysis phase, the skill instructs the agent to execute a local Python script (scripts/mem0-cli.py) to log project metadata. This facilitates integration with long-term memory systems.
  • [DATA_EXPOSURE]: The skill performs read and write operations on files within the .forgewright/ directory. These operations are limited to project-specific requirement documents, stakeholder analyses, and handoff packages, conforming to standard workspace usage.
Audit Metadata
Risk Level
SAFE
Analyzed
May 1, 2026, 07:55 AM
Security Audit — agent-trust-hub — business-analyst