learning-product
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill references internal organizational tools (e.g.,
ane_package.reporting,pptx_export.write_pptx_deck) to generate formatted files (Word, PDF, PowerPoint). These are documented as platform-specific entry points for document generation rather than arbitrary shell execution. - [DATA_EXFILTRATION]: The skill performs legitimate network operations via
WebFetchandWebSearchfor the sole purpose of auditing and verifying the canonical sources of existing URLs (DOI resolution, 404 checks). It does not access sensitive local files or transmit user data to unauthorized third-party domains. - [PROMPT_INJECTION]: The skill contains strict 'quality gates' and 'writing rules' that enforce specific personas (Tier 1 working brief) and structural integrity. It does not attempt to bypass safety filters or override system-level instructions; rather, it sets internal stylistic constraints to ensure organizational alignment.
- [EXTERNAL_DOWNLOADS]: The skill downloads/reads reference materials from internal paths (e.g.,
literature-reviews/,agent-improvements/) and utilizes standard research aggregators (e.g., ResearchGate, PMC) for URL verification. All external sources are accessed within the scope of document auditing and citation verification. - [REMOTE_CODE_EXECUTION]: No remote code execution patterns were found. The skill uses pre-defined model selection policies for specific narrative drafting but does not execute external scripts or untrusted code.
Audit Metadata