data-workstream-foundation
Pass
Audited by Gen Agent Trust Hub on Aug 19, 2026
Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
- [Command Execution]: The skill integrates a sensitive content scanner via a local script execution (
scripts/scan_sensitive_content.py). This script, sourced from a related internal skill, is used as a security gate to detect and prevent the accidental exposure of storage keys, bearer tokens, or other credentials in durable artifacts. - [Indirect Prompt Injection Protections]: The skill provides clear instructions regarding 'Untrusted-content boundaries.' These guidelines direct the agent to treat ingested artifacts and tool outputs strictly as data for analysis rather than as instructions to follow, providing a defensive layer against attacks embedded in processed files.
Audit Metadata