gpu-customer-usage-conversion

Pass

Audited by Gen Agent Trust Hub on Jul 7, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes a bundled shell script (scripts/collect_gpu_customer_usage.sh) which in turn executes multiple commands using the dce command-line utility. This is used for gathering system evidence and is limited to read-only operations as per the instructions.
  • [EXTERNAL_DOWNLOADS]: No external downloads or remote script executions were identified. All scripts and tools used appear to be local or part of the environment.
  • [DATA_EXFILTRATION]: While the skill accesses sensitive business data such as billing information and resource usage, it stores this data in a local temporary directory for the agent's analysis. No evidence of data being transmitted to external unauthorized domains was found.
  • [PROMPT_INJECTION]: The instructions do not contain patterns that attempt to bypass safety filters or override core agent behavior.
  • [DYNAMIC_EXECUTION]: The skill uses a shell script to dynamically construct and execute commands based on user-provided parameters (host, cluster, workspace). This is an expected and documented functionality for data collection.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 7, 2026, 02:22 AM
Security Audit — agent-trust-hub — gpu-customer-usage-conversion