revops-radar

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill fetches content from external RevOps-related URLs (such as Substack, LinkedIn, and practitioner blogs) to verify their 'freshness' and last-confirmed publication date. This introduces a surface where malicious instructions could theoretically be injected into the external content to influence the agent. However, the risk is mitigated by the skill's narrow focus on identifying dated items and confirming topical relevance, rather than executing commands or following arbitrary text.
  • Ingestion points: External URLs provided in references/sources.md and references/people-to-follow.md.
  • Boundary markers: Semantic boundaries are established by instructions to 'find the most recent dated item' and match the 'source's subject'.
  • Capability inventory: Uses network fetching for link verification; no file-write or shell execution capabilities are present.
  • Sanitization: Includes verification logic to detect redirects, domain resale, and content mismatches.
  • [EXTERNAL_DOWNLOADS]: The skill performs network operations to fetch metadata and verify the status of various information sources. These requests target established and well-known industry platforms such as Salesforce, LinkedIn, Substack, and Reddit. These operations are essential for the skill's primary function and do not involve the installation of unverified software or execution of remote code.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:18 PM
Security Audit — agent-trust-hub — revops-radar