matematic-konstytucja-ai
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]: The skill's methodology documentation for 'Shadow AI Discovery' explicitly identifies sensitive file paths, specifically mentioning the detection of API keys within
.envfiles in project environments. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external discovery surveys and environment inventories to generate governance documents.
- Ingestion points: Discovery reports and Shadow AI inventory inventories described in
SKILL.md(Discovery phase). - Boundary markers: None identified in the instruction set.
- Capability inventory: The skill has file read and write capabilities (
allowed-tools: [Read, Write]). - Sanitization: No specific sanitization or filtering protocols are defined for handling content discovered during environment scans.
- [EXTERNAL_DOWNLOADS]: The skill references and directs users to external methodologies and documentation located at
genai.owasp.org,docs.icme.io, and various GitHub repositories (e.g.,hshadab/preflight-mike,open-metadata/OpenMetadata). It also incorporates patterns from a toolkit provided by a well-known service provider.
Audit Metadata