data-workstream-foundation

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [Command Execution]: The skill integrates a sensitive content scanner via a local script execution (scripts/scan_sensitive_content.py). This script, sourced from a related internal skill, is used as a security gate to detect and prevent the accidental exposure of storage keys, bearer tokens, or other credentials in durable artifacts.
  • [Indirect Prompt Injection Protections]: The skill provides clear instructions regarding 'Untrusted-content boundaries.' These guidelines direct the agent to treat ingested artifacts and tool outputs strictly as data for analysis rather than as instructions to follow, providing a defensive layer against attacks embedded in processed files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 11:39 PM
Security Audit — agent-trust-hub — data-workstream-foundation