consult-sofia

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill documents how to delegate specific troubleshooting and evaluation tasks to Sofia, an official Coval-managed service. It includes explicit constraints to ensure the agent does not include sensitive information like API keys or credentials in its requests.
  • [SAFE]: The skill references an official remote MCP connection point at https://mcp.coval.dev/mcp which is the authorized service domain for the author. This is used for providing grounded analysis based on the organization's existing telemetry and monitoring data.
  • [SAFE]: While the skill ingests and processes untrusted data (user requests and run IDs), it defines a strict output contract and specifies that 'consult_sofia' is a read-only specialist that cannot mutate or create resources, limiting the potential impact of indirect instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 04:54 AM
Security Audit — agent-trust-hub — consult-sofia