engagement-terms-billing-guidelines

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No override markers, bypass instructions, or jailbreak attempts were found in the instructional body or metadata.
  • [DATA_EXFILTRATION]: The skill does not access sensitive local file paths (e.g., SSH keys, credentials) or perform unauthorized network operations. References to external organizations (e.g., ACC, CLOC) and public legal guidelines (City of Chicago, Georgia Tech) are used for context and validation in line with the skill's primary purpose.
  • [REMOTE_CODE_EXECUTION]: There are no patterns suggesting the download or execution of remote scripts or binaries.
  • [COMMAND_EXECUTION]: The skill does not use shell commands or perform system-level operations. It uses the platform's document generation capabilities to produce .docx files.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or tokens were detected. The skill correctly instructs users to provide context manually or through standard platform connectors.
  • [INDIRECT_PROMPT_INJECTION]: While the skill ingests external data (user-provided legal documents for gap analysis), it lacks dangerous capabilities such as network exfiltration or code execution that could be exploited via injection. The risk is considered negligible given the skill's scope as a writing assistant.
  • [OBFUSCATION]: No encoded strings, homoglyphs, or hidden characters were detected in the files.
  • [NO_CODE]: This skill consists entirely of markdown instructions and documentation, with no executable logic or scripts included.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:33 PM
Security Audit — agent-trust-hub — engagement-terms-billing-guidelines