enterprise-business-continuity

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill uses clear, instructional language to guide the AI agent in disaster recovery planning. It contains no attempts to bypass safety filters or override core system instructions. While it uses assertive formatting instructions (e.g., 'No preamble'), these are standard for optimizing output efficiency and are not malicious.
  • [DATA_EXFILTRATION]: The skill does not contain hardcoded credentials, API keys, or instructions to read sensitive environment files. The provided Python calculator examples are purely local math functions with no network or file system operations.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving remote script downloads (e.g., curl|bash) or installations from unverified repositories. The skill references legitimate third-party business services (Stripe, Cloudflare) as part of strategic vendor fallback documentation, not as software dependencies.
  • [COMMAND_EXECUTION]: No shell commands or system-level modifications are present. The skill focuses on documentation, planning methodologies, and communication templates.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to ingest business data (revenue, service lists) to generate BCP artifacts, it does not provide the agent with tools that could be abused via injected data. The output is constrained to text-based planning documents.
  • [DYNAMIC_CONTEXT_INJECTION]: The skill does not utilize dynamic context injection syntax (!command) to execute shell operations at load time.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 09:45 AM
Security Audit — agent-trust-hub — enterprise-business-continuity