cali-degustia-diagnostico

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection (Category 8) because it ingests untrusted client transcripts and interpolates that data into HTML templates. An attacker could theoretically place malicious instructions or scripts within a transcript to influence the agent's behavior or target the viewer of the generated HTML report. While the skill instructs the agent to 'extract without inventing,' it lacks explicit boundary markers or sanitization logic for the interpolated content.
  • [COMMAND_EXECUTION]: The skill includes several local shell scripts (scripts/check-faixas.sh, scripts/validate-markers.sh, scripts/validate-report.sh) used for automated validation of the generated HTML reports. These scripts perform benign pattern matching (using grep) to ensure report quality and consistency.
  • [EXTERNAL_DOWNLOADS]: The skill's tool catalog (references/ferramentas.md) references numerous well-known technology services and open-source projects (e.g., n8n, Cal.com, Baserow, Notion, Tally, Pipefy, Airtable). These references are used for research and recommendation purposes for the client and do not involve the skill downloading or executing untrusted remote code at runtime.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 03:00 AM
Security Audit — agent-trust-hub — cali-degustia-diagnostico