employee-management

Pass

Audited by Gen Agent Trust Hub on Aug 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is primarily composed of instructional documentation and note templates for people management. It follows security best practices by delegating file operations to a dedicated 'second-brain' utility and instructing the agent to summarize sensitive personal details rather than transcribing them verbatim.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data such as employee names and performance topics to create vault entries via a local CLI tool (vault.sh). While this provides a theoretical injection surface, the skill implements safety guidelines by directing the agent to use privacy markers and summarize external content, minimizing the risk of processing malicious instructions embedded in user data.
  • [COMMAND_EXECUTION]: The skill uses the vault.sh utility to perform structured data capture. The command patterns provided in the instructions are restricted to specific capture tasks (1:1 logs, feedback) and include explicit privacy flags (sensitivity=private), representing a controlled and legitimate use of shell tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 18, 2026, 07:15 PM
Security Audit — agent-trust-hub — employee-management