sop-creator
Pass
Audited by Gen Agent Trust Hub on Jun 19, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues were detected. The skill's content is purely educational and instructional, focusing on business process documentation and management.
- [NO_CODE]: The skill consists entirely of Markdown text. It does not include any scripts (Python, JavaScript, shell), configuration files, or command execution strings.
- [DATA_EXPOSURE_AND_EXFILTRATION]: The skill mentions common business systems (e.g., Totvs Protheus, SharePoint, CRM) as examples in templates, but it does not contain hardcoded credentials, API keys, or instructions to access sensitive local files.
- [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process user-provided tasks to generate SOPs, it lacks instructions to execute code or call external tools based on that input, minimizing the surface for injection-based attacks.
Audit Metadata