affiliate-performance-dashboard
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No security issues or malicious patterns were detected across the analyzed files.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs during an 'Interview' workflow to generate dashboard specifications. While it lacks explicit sanitization or boundary markers for these inputs, the risk is negligible as the skill's capabilities are limited to generating documentation and do not include code execution, file system modifications, or network operations.
- [DATA_EXPOSURE]: The skill does not contain hardcoded credentials, sensitive file paths (e.g., .ssh, .aws), or any mechanisms for data exfiltration.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving external package installations (pip, npm) or remote script execution (curl | bash).
- [OBFUSCATION]: No obfuscated content, such as Base64-encoded strings, zero-width characters, or homoglyphs, was found in the skill or its references.
Audit Metadata