correlation-insights

Pass

Audited by Gen Agent Trust Hub on Jun 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill uses ServiceNow-specific tools (MCP and REST) to query standard tables like sn_si_incident, sn_ti_observable, and sn_vul_vulnerable_item. These are routine operations for a Security Operations (SecOps) role.
  • [SAFE]: All external references and metadata point to legitimate SecOps practices and the stated author, Happy Technologies LLC.
  • [COMMAND_EXECUTION]: The skill mentions 'Bash' in the native tools section and includes a placeholder for SN-Execute-Background-Script. While these can be powerful, they are documented here within the context of ServiceNow administrative tasks and do not show any signs of malicious use or command injection. The usage is consistent with the 'advanced' complexity and SecOps purpose of the skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 14, 2026, 01:53 PM
Security Audit — agent-trust-hub — correlation-insights