four-core-documents

Pass

Audited by Gen Agent Trust Hub on Aug 12, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill performs expected business analysis and document generation tasks. It interacts only with project-specific files and uses authorized local tools for state management, following the intended functional design without security violations.- [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface as it reads from external market research and client input files. 1. Ingestion points: Data is sourced from profile.json, stone-facts.json, and the part-02-external-research/ directory. 2. Boundary markers: The instructions do not specify the use of delimiters or 'ignore' warnings for external content. 3. Capability inventory: The skill has access to Read, Write, Edit, and Bash tools. 4. Sanitization: No explicit sanitization or filtering logic is provided for the processed content. Despite these surface-level characteristics, the risk is considered negligible given the highly structured nature of the production methodology.- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute local administrative scripts such as engagement-state.py. These operations are used for internal version control and project state updates, representing standard vendor functionality within the local workspace.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 12, 2026, 10:15 PM
Security Audit — agent-trust-hub — four-core-documents