skills/clawic/skills/Agency/Gen Agent Trust Hub

Agency

Pass

Audited by Gen Agent Trust Hub on Jun 6, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of organizational markdown documentation and templates for agency management. No executable scripts, binary files, or suspicious command-line operations were detected.
  • [PROMPT_INJECTION]: The workflow involves processing external data (client intake and feedback), which creates a surface for indirect prompt injection. This is classified as low risk due to the absence of exploitable capabilities.
  • Ingestion points: Intake process in 'onboarding.md' and feedback parsing in 'communication.md'.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the templates.
  • Capability inventory: The skill is restricted to local file operations within '~/agency/'. It has no access to subprocesses, network requests, or sensitive system directories.
  • Sanitization: There are no documented steps for sanitizing or validating the content of ingested client communications.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 6, 2026, 07:52 AM
Security Audit — agent-trust-hub — Agency