matematic-konstytucja-ai

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: The skill's methodology documentation for 'Shadow AI Discovery' explicitly identifies sensitive file paths, specifically mentioning the detection of API keys within .env files in project environments.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external discovery surveys and environment inventories to generate governance documents.
  • Ingestion points: Discovery reports and Shadow AI inventory inventories described in SKILL.md (Discovery phase).
  • Boundary markers: None identified in the instruction set.
  • Capability inventory: The skill has file read and write capabilities (allowed-tools: [Read, Write]).
  • Sanitization: No specific sanitization or filtering protocols are defined for handling content discovered during environment scans.
  • [EXTERNAL_DOWNLOADS]: The skill references and directs users to external methodologies and documentation located at genai.owasp.org, docs.icme.io, and various GitHub repositories (e.g., hshadab/preflight-mike, open-metadata/OpenMetadata). It also incorporates patterns from a toolkit provided by a well-known service provider.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 09:44 PM
Security Audit — agent-trust-hub — matematic-konstytucja-ai