executive-dashboard

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's functionality aligns with its stated purpose of generating executive dashboards and ITSM metrics. It uses well-documented ServiceNow interaction patterns without any signs of malicious intent or deceptive behavior.
  • [COMMAND_EXECUTION]: The skill utilizes the SN-Execute-Background-Script tool to run server-side ServiceNow scripts for data aggregation. This is an expected use of the tool for advanced reporting tasks and is explicitly listed in the skill's permitted tools configuration.
  • [PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests data from external ServiceNow records (e.g., incident descriptions). However, the skill's logic is focused on structured queries and numerical calculations (MTTR, MTBF, success rates), which minimizes the risk of the agent interpreting record data as instructions. The use of specific tool parameters for queries serves as a functional boundary.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:34 PM
Security Audit — agent-trust-hub — executive-dashboard