automation

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data through webhooks and retrieval-augmented generation (RAG) pipelines. 1. Ingestion points: External API responses and webhook payloads (references/integrations.md) and knowledge base corpora (references/rag.md). 2. Boundary markers: The skill includes explicit instructions to isolate system instructions from untrusted user data and maintain prompt-injection boundaries (references/prompt.md). 3. Capability inventory: The skill has access to shell execution (bash, run_command) and file system modifications (write_to_file, replace_file_content). 4. Sanitization: Procedures include HMAC signature verification for webhooks and mandatory validation/sanitization of inbound payloads (references/integrations.md).
  • [SAFE]: The skill implements strong credential security practices, directing the use of external secret stores like Bitwarden and emphasizing that secrets must never be stored in code or logs.
  • [SAFE]: Browser automation (Browser Relay) includes specific privacy guardrails, such as binding to the local loopback interface and redacting sensitive financial or personal information before logging.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 09:23 PM
Security Audit — agent-trust-hub — automation