ci-discovery
Pass
Audited by Gen Agent Trust Hub on Apr 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or vulnerabilities detected. The skill provides legitimate procedures for CMDB discovery and maintenance using standard ServiceNow integration tools.
- [SAFE]: Indirect Prompt Injection Surface. The skill reads data from external ServiceNow tables which is an inherent part of CMDB management. Ingestion points: Data is retrieved from ServiceNow via SN-Query-Table and SN-List-CmdbCis in SKILL.md. Boundary markers: Absent. Capability inventory: Access to Bash and ServiceNow write operations (SN-Update-Record, SN-Create-Record) in SKILL.md. Sanitization: No explicit validation of retrieved CMDB content is performed before processing. This is considered acceptable within the context of administrative IT workflows.
Audit Metadata