task-summarization

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill reads task details, priority, and activity logs from ServiceNow tables to generate summaries. This internal data access is restricted to the ServiceNow environment and is consistent with the skill's administrative purpose.
  • [COMMAND_EXECUTION]: The skill mentions administrative capabilities such as SN-Execute-Background-Script and Bash. While these are high-privilege tools, they are standard within the ServiceNow ecosystem for its intended users (e.g., ITIL or admin roles) and are not used for unauthorized execution in the procedure.
  • [EXTERNAL_DOWNLOADS]: The skill references documentation hosted on ServiceNow's official GitHub repository. These are trusted sources providing context for platform features.
  • [PROMPT_INJECTION]: The skill ingests user-provided content from task journal entries to produce summaries, representing a surface for indirect prompt injection. This is inherent to the summarization task and is handled within the platform's context. 1. Ingestion points: SKILL.md (Step 2: Query sys_journal_field). 2. Boundary markers: Absent. 3. Capability inventory: SKILL.md (SN-Add-Work-Notes, SN-Execute-Background-Script). 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 02:23 PM
Security Audit — agent-trust-hub — task-summarization