weekly-ops-report
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill references external GitHub repositories (gulmezeren2-byte/auto-report-pipeline and gulmezeren2-byte/industrial-engineering-ai-skills) as the source and implementation of the reporting logic. These resources are from a third-party developer and are not verified by a trusted organization.
- [PROMPT_INJECTION]: The skill contains a surface for indirect prompt injection through its ingestion of external data. 1. Ingestion points: The skill processes raw operational data from external sources (SKILL.md). 2. Boundary markers: No instructions are provided to the agent to distinguish between the input data and its internal instructions. 3. Capability inventory: The skill outlines complex data cleaning and KPI reporting logic, although no specific tool permissions are granted in this skill file. 4. Sanitization: There is no requirement for validation, escaping, or filtering of the raw input data to prevent instruction override.
Audit Metadata