process-automation-audit

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No attempts to override safety guidelines or bypass agent constraints were found. The core rules focus on business engagement boundaries and pricing discipline.
  • [DATA_EXFILTRATION]: No evidence of hardcoded credentials, sensitive file access, or network exfiltration. While the skill guides the agent to process business data (invoices, ERP handoffs), it does not define any unauthorized external transmission mechanisms.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns, external scripts, or untrusted package dependencies were detected.
  • [COMMAND_EXECUTION]: The skill does not contain any shell commands, subprocess spawning, or dynamic context injection via the exclamation-backtick syntax.
  • [OBFUSCATION]: No hidden content, Base64 encoding, homoglyphs, or zero-width characters were identified in any of the skill files.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest external data (process maps, sample documents, interviews) which constitutes a typical ingestion surface. However, there are no exploitable capabilities (like code execution or file-system writes) present that would allow an attacker to leverage this surface for an attack.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:05 AM
Security Audit — agent-trust-hub — process-automation-audit