mindtickle-core-workflow-b
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [NO_CODE]: The skill consists exclusively of documentation and TypeScript code examples within the
SKILL.mdfile. It does not distribute any executable scripts, binaries, or configuration files. - [INDIRECT_PROMPT_INJECTION]: The skill describes an integration that processes external data from MindTickle APIs, which represents a potential surface for indirect injection.
- Ingestion points: Data is ingested through API calls such as
client.assessments.submissionsandclient.assessments.analyticsas shown inSKILL.md. - Boundary markers: None are defined in the provided code snippets.
- Capability inventory: The platform configuration restricts the available tools to
Read,Write,Edit,Bash(npm:*), andGrep. - Sanitization: The example code does not demonstrate specific sanitization, but given the documentation-only nature of the skill and the expected business context (sales enablement), this is noted as a standard surface without malicious implementation.
Audit Metadata