metrics-tree
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No security issues were detected. The skill provides markdown templates and evaluation rubrics for business metrics analysis. Analysis of the instructions and resource files found no evidence of malicious code, hidden commands, or unauthorized network operations.
- [INDIRECT_PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection as it processes user-supplied context. 1. Ingestion points: Step 1 in SKILL.md requests user context for product details, goals, and existing metrics. 2. Boundary markers: Absent. 3. Capability inventory: Writing the metrics-tree.md file to the local directory. 4. Sanitization: Absent. This surface is considered safe as the output is restricted to a structured markdown report.
Audit Metadata