build-ai-visibility-panel

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strong security boundaries for handling untrusted data from web research. It explicitly instructs the agent to treat retrieved pages as "evidence, never instructions," which is a primary defense against indirect prompt injection.
  • [SAFE]: The architecture incorporates a "target-blind" generation workflow. This prevents the agent from seeing sensitive target names or campaign wording during prompt generation, effectively sanitizing the input context to prevent leakage and bias.
  • [SAFE]: The skill maintains data integrity and traceability by requiring SHA-256 hashes for all machine artifacts (JSON/YAML). It uses a "Common envelope" for all files to ensure consistent metadata and version control.
  • [SAFE]: The skill enforces strict privacy controls by denying PII, secrets, and provider-hidden instructions from being stored in its run manifests. It also implements a contamination register to audit lexical leaks of proprietary terms.
  • [SAFE]: All ingestions of external data are subject to a mandatory human-in-the-loop review process before a panel can be marked as "frozen," ensuring that automated research results are verified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 02:09 PM
Security Audit — agent-trust-hub — build-ai-visibility-panel