chro-advisor

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's functionality is limited to localized data analysis and providing strategy recommendations. The Python scripts process user-provided data structures for HR metrics without external dependencies or network calls.
  • [SAFE]: No evidence of prompt injection, data exfiltration, or persistence mechanisms was found. The instructions in SKILL.md and the reference documents are consistent with the stated purpose of an HR advisor.
  • [SAFE]: The skill uses a transparent logic for handling sensitive information within its reporting functions, with no unauthorized side effects.
  • [SAFE]: The scripts use standard JSON and CSV parsing which do not present significant code injection risks in this context.
  • [SAFE]: While the skill ingests data from external JSON files, the risk of indirect prompt injection is negligible because the scripts have no side-effect capabilities such as network access, shell execution, or file writing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 06:58 PM
Security Audit — agent-trust-hub — chro-advisor