audit-analytics

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it requires the agent to ingest and interpret external source code and analytics configuration files.
  • Ingestion points: Processes application source code (e.g., layout.tsx), tracking calls (e.g., track()), and analytics platform schemas.
  • Boundary markers: The instructions include a mandatory 'Self-critique' phase and a 'Definition of Done' to verify logical consistency and prevent unauthorized changes.
  • Capability inventory: The skill is explicitly defined as 'Read-only' and focuses on proposing taxonomies rather than executing code, making network requests, or writing to the filesystem.
  • Sanitization: Strict instructions are included to prevent the reporting of PII (Personal Identifiable Information) values, limiting output to property names and taxonomy metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 05:55 AM
Security Audit — agent-trust-hub — audit-analytics