unified-notifications-ops

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional markdown and YAML configuration. No executable code, shell commands, or network operations are included in the skill definition.\n- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external event data from GitHub and Linear. While this represents a potential ingestion surface for indirect prompt injection, the risk is addressed through instructional guardrails. \n
  • Ingestion points: GitHub issues, PRs, status updates, and Linear project data (SKILL.md).\n
  • Boundary markers: Explicit instruction to "never expose tokens, secrets, webhook secrets, or internal identifiers".\n
  • Capability inventory: No code is present to perform file-writes, network exfiltration, or subprocess execution.\n
  • Sanitization: None explicitly mentioned in the workflow, though the skill mandates high-level classification and collapse of incoming signals.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — unified-notifications-ops