signal-scoring

Pass

Audited by Gen Agent Trust Hub on Jul 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security vulnerabilities were identified in the skill's instructions or scripts.
  • [DATA_EXPOSURE]: The skill defines a process for gathering public business data (hiring, funding, tech stack) for scoring purposes. It does not attempt to access sensitive user files or credentials.
  • [COMMAND_EXECUTION]: The provided script scripts/check-output.py is a benign utility that validates the presence of specific keywords in a text file. It does not execute external commands or use unsafe functions.
  • [INDIRECT_PROMPT_INJECTION]: While the skill is designed to process data from external sources (such as job boards and news sites), it follows a structured scoring methodology and lacks capabilities (like dynamic code execution) that would make it vulnerable to high-risk injection attacks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 16, 2026, 03:20 PM
Security Audit — agent-trust-hub — signal-scoring