workspace-health-monitor

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's primary function is to analyze user-provided text files and generate a structured audit report. All instructions are consistent with the stated purpose of workspace hygiene and organization.
  • [SAFE]: Static analysis identified potential homoglyphs in 'docs/USER-GUIDE.ru.md'. Review confirms these are legitimate Cyrillic characters used correctly in the Russian language version of the documentation and do not represent a security threat.
  • [SAFE]: The skill requests access to workspace files via standard platform features like Cowork folder access or manual upload. This is necessary for its core functionality and is used solely for internal analysis and reporting within the agent's context. No network exfiltration or destructive file operations (deletion/modification) are requested.
  • [PROMPT_INJECTION]: The skill processes untrusted external data (user workspace files) for analysis. This presents a potential surface for indirect prompt injection; however, the risk is negligible as the skill lacks capabilities for network access, file modification, or high-privilege command execution. Mandatory Evidence Chain: (1) Ingestion points: User files via Cowork/upload/paste (SKILL.md Step 1). (2) Boundary markers: None explicitly defined. (3) Capability inventory: File reading and text report generation. (4) Sanitization: None defined.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 09:40 AM
Security Audit — agent-trust-hub — workspace-health-monitor