performance-scorecard

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions and documentation are consistent with the stated purpose of managing legal firm performance. No patterns of prompt injection, credential harvesting, or unauthorized remote execution were found.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a potential surface for indirect prompt injection because it is instructed to search for and incorporate data from external sources such as Google Drive and project knowledge repositories.
  • Ingestion points: The 'Pre-flight' section in SKILL.md directs the agent to search project knowledge and Google Drive for performance reports and billing summaries.
  • Boundary markers: None explicitly defined; the skill uses structured templates to contain the ingested data.
  • Capability inventory: The skill is designed to output text and generate .docx files. It lacks capabilities for subprocess execution, network exfiltration to untrusted domains, or sensitive file modifications.
  • Sanitization: There are no instructions for sanitizing or validating the content retrieved from searched files before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:34 PM
Security Audit — agent-trust-hub — performance-scorecard