ci-discovery

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or vulnerabilities detected. The skill provides legitimate procedures for CMDB discovery and maintenance using standard ServiceNow integration tools.
  • [SAFE]: Indirect Prompt Injection Surface. The skill reads data from external ServiceNow tables which is an inherent part of CMDB management. Ingestion points: Data is retrieved from ServiceNow via SN-Query-Table and SN-List-CmdbCis in SKILL.md. Boundary markers: Absent. Capability inventory: Access to Bash and ServiceNow write operations (SN-Update-Record, SN-Create-Record) in SKILL.md. Sanitization: No explicit validation of retrieved CMDB content is performed before processing. This is considered acceptable within the context of administrative IT workflows.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 04:35 PM
Security Audit — agent-trust-hub — ci-discovery