script-includes
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists entirely of educational documentation and code snippets for ServiceNow development. It does not contain executable malicious code, obfuscation, or instructions designed to bypass security controls.
- [COMMAND_EXECUTION]: While the skill lists
BashandSN-Execute-Background-Scriptas allowed tools, these are standard for ServiceNow administrative and development workflows. The usage within the skill body is purely instructional for creating and testing server-side scripts. - [DATA_EXFILTRATION]: There is no evidence of unauthorized data access or exfiltration. The included examples (such as REST API calls for SMS notifications) are standard integration patterns used in ServiceNow development.
- [PROMPT_INJECTION]: The content does not include any instructions aimed at overriding agent behavior, extracting system prompts, or bypassing safety guardrails.
Audit Metadata