performance-scorecard
Pass
Audited by Gen Agent Trust Hub on Jun 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill instructions and documentation are consistent with the stated purpose of managing legal firm performance. No patterns of prompt injection, credential harvesting, or unauthorized remote execution were found.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential surface for indirect prompt injection because it is instructed to search for and incorporate data from external sources such as Google Drive and project knowledge repositories.
- Ingestion points: The 'Pre-flight' section in SKILL.md directs the agent to search project knowledge and Google Drive for performance reports and billing summaries.
- Boundary markers: None explicitly defined; the skill uses structured templates to contain the ingested data.
- Capability inventory: The skill is designed to output text and generate .docx files. It lacks capabilities for subprocess execution, network exfiltration to untrusted domains, or sensitive file modifications.
- Sanitization: There are no instructions for sanitizing or validating the content retrieved from searched files before it is processed by the agent.
Audit Metadata