kpi-digest-builder

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: No external downloads or remote dependencies are utilized by this skill.
  • [DATA_EXFILTRATION]: No network operations or data transmission patterns were detected. The skill only processes local workspace files (.md, .txt, .csv) and produces text output to the user.
  • [REMOTE_CODE_EXECUTION]: No remote code execution or script invocation patterns were identified. The skill explicitly states it requires no additional tools or integrations.
  • [COMMAND_EXECUTION]: The skill does not perform any shell command execution or subprocess spawning.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or sensitive credential access patterns were found.
  • [PROMPT_INJECTION]: The instructions do not contain any attempts to bypass safety filters or override agent behavior.
  • [SAFE]: The skill follows its stated purpose of reading local metrics data and formatting it into a report.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 09:40 AM
Security Audit — agent-trust-hub — kpi-digest-builder