workhuman-security-basics

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is a standard security auditing template designed for reviewing Workhuman SaaS integrations. It defines a shared-responsibility model and provides structured instructions for threat modeling and control verification.
  • [EXTERNAL_DOWNLOADS]: The skill includes links to official documentation on workhuman.com. The use of the WebFetch tool is restricted by the instructions to verifying official first-party security commitments from well-known service domains.
  • [DATA_EXFILTRATION]: There is no evidence of unauthorized data exfiltration. The skill focuses on documentation and threat modeling, with explicit instructions to redact sensitive evidence and observability data.
  • [INDIRECT_PROMPT_INJECTION]: While the skill processes data regarding tenant configurations and integrations, it does so in an analytical context. It does not possess capabilities that would make it vulnerable to typical injection attacks, and its instructions focus on structured security assessments.
  • [NO_CODE]: The skill does not include any scripts, executables, or package dependencies, relying entirely on the agent's built-in file and web retrieval tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 10:04 AM
Security Audit — agent-trust-hub — workhuman-security-basics