audit-analytics
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it requires the agent to ingest and interpret external source code and analytics configuration files.
- Ingestion points: Processes application source code (e.g., layout.tsx), tracking calls (e.g., track()), and analytics platform schemas.
- Boundary markers: The instructions include a mandatory 'Self-critique' phase and a 'Definition of Done' to verify logical consistency and prevent unauthorized changes.
- Capability inventory: The skill is explicitly defined as 'Read-only' and focuses on proposing taxonomies rather than executing code, making network requests, or writing to the filesystem.
- Sanitization: Strict instructions are included to prevent the reporting of PII (Personal Identifiable Information) values, limiting output to property names and taxonomy metadata.
Audit Metadata