value-modeler
Pass
Audited by Gen Agent Trust Hub on Jul 25, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute standard commands for configuration management (such as 'jq' for JSON parsing) and to call internal vendor utility scripts (e.g., 'wiki-grounding.py') within the trusted environment.
- [EXTERNAL_DOWNLOADS]: During Phase 2.6, the skill performs automated industry research via web searches to find publicly available case studies and references to enrich its solution templates.
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by processing external research data and workspace files. This is mitigated through explicit escaping in the HTML UI and the use of structured data processing.
- [SAFE]: All operations are consistent with the skill's stated purpose of business modeling and strategy. No evidence of credential exfiltration, privilege escalation, or persistence mechanisms was found.
Audit Metadata