skills/gcpaas/dataroom/dataroom-page/Gen Agent Trust Hub

dataroom-page

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses natural instructional language to guide the agent through a specific workflow. No bypass attempts, role-play injections, or instructions to disregard safety filters were detected. The use of 'IMPORTANT' and 'CRITICAL' in the developer instructions refers to configuration accuracy rather than instruction overriding.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill interacts exclusively with a defined MCP server toolset. It does not attempt to access sensitive system files (e.g., credentials, SSH keys, .env files) or exfiltrate data to non-whitelisted or suspicious domains. It manages page configuration data which is consistent with its stated purpose.
  • [COMMAND_EXECUTION]: Tool usage is limited to the dataroom-mcp-server interface. There are no patterns suggesting shell command execution, subprocess spawning, or the use of privileged commands like sudo.
  • [REMOTE_CODE_EXECUTION]: No external script downloads, package installations, or piped remote execution patterns were found. The skill relies on predefined tools within the execution environment.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes component configurations and user requirements to build JSON structures. While it ingests data from tool outputs, the surface is limited to structural UI configuration and does not interpolate untrusted data into high-privilege execution contexts without clear intent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 09:16 AM
Security Audit — agent-trust-hub — dataroom-page