execute-action

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a robust defense against indirect prompt injection by explicitly instructing the agent to treat action descriptions and quoted content as data only, ignoring any embedded instructions meant to bypass safety or change behavior.
  • [COMMAND_EXECUTION]: The skill manages high-privilege operations, including interactions with external communication tools (Gmail, Linear) and the invocation of other workspace skills. These capabilities are the primary purpose of the skill and are restricted to instructions from an upstream orchestrator and, for non-draft actions, are subjected to a mandatory validation gate.
  • [DATA_EXFILTRATION]: Although the skill handles data through tools like Gmail, it operates in a strictly functional manner, returning only artifact references (traces) to the calling orchestrator without sending data to unauthorized external endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 12:19 PM
Security Audit — agent-trust-hub — execute-action