stci-dataops
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill uses Python-scoped Bash commands to run tests ('pytest') and the collector pipeline ('services.collector.pipeline'). While these are high-capability tools, they are appropriately restricted to specific task domains within the skill's operational workflow.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from the web, creating a potential surface for indirect prompt injection.
- Ingestion points: External pricing provider documentation, APIs, and pages are retrieved using 'WebFetch' and 'WebSearch' (SKILL.md, Workflow Step 3).
- Boundary markers: The skill implements strict schema validation against 'schemas/observation.schema.json' and unit tests for normalization (SKILL.md, Validation section).
- Capability inventory: The skill utilizes capabilities to modify the repository ('Write', 'Edit') and execute Python commands ('Bash(python:*)') for testing and validation.
- Sanitization: The instructions mandate redacting secrets and minimizing payloads before storage or processing (SKILL.md, Validation section).
- [EXTERNAL_DOWNLOADS]: The skill fetches pricing data and documentation from external provider URLs and APIs to build evidence packets and source profiles.
Audit Metadata