opc-dashboard-review
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill restricts its file operations to the
opc-doc/subdirectory within the current working directory. This scoping ensures that the agent's read and write capabilities are limited to relevant project data. - [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface required for its primary function, though the risk is negligible as it processes its own historical outputs:
- Ingestion points: Reads data from
opc-doc/outputs/**andopc-doc/reviews/dashboard.jsonas defined inSKILL.md. - Boundary markers: No explicit boundary markers or "ignore" instructions are present for the ingested data.
- Capability inventory: The skill employs the
Writetool to persist review results to the local filesystem. - Sanitization: No specific content sanitization logic is described in the instructions.
- [SAFE]: No network operations (such as curl or wget), external dependencies, or remote code execution patterns were detected. The skill logic is entirely prompt-driven and uses local reference documents for its framework.
Audit Metadata