grow-track-starter-kit
Pass
Audited by Gen Agent Trust Hub on Sep 18, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill consists of instructional text for HR planning and does not contain malicious code or commands.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from Lattice MCP tools and user-provided HR documents (ingestion points) but provides explicit instructions to treat retrieved text as untrusted and ignore embedded instructions (boundary markers). The skill is limited to generating text recommendations and lacks unauthorized write or execute capabilities (capability inventory). It also mandates human review for all employment-related outputs (sanitization).
Audit Metadata