daily-brief
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the GitHub CLI (
gh) to search for pull requests, issues, and review requests across all of the user's repositories. These commands are localized to the user's authenticated environment and are necessary for the skill's stated purpose. - [EXTERNAL_DOWNLOADS]: The skill utilizes Model Context Protocol (MCP) tools to access seven different productivity platforms. This data access is used exclusively for aggregation and is governed by strict read-only constraints described in the workflow.
- [SAFE]: The skill identifies and mitigates the risk of indirect prompt injection (Category 8) inherent in processing untrusted external data. It implements a mandatory evidence chain including: Ingestion Points (Gmail, Slack, etc.), Boundary Markers (confidence-level labels and coverage statements), Capability Inventory (read-only tools and local file writes), and Sanitization (summarization and live re-verification of item status). The requirement to re-verify item status against live platforms before generating continuity reports is a particularly effective control against the persistence of malicious or incorrect data.
Audit Metadata