67-agency-vendor-brief-global

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides structured guidance and templates for vendor management, focusing on operational efficiency and risk mitigation through clear documentation.
  • [DATA_EXPOSURE]: The template includes placeholders for business contact information (names, emails, phones) and budget details. However, it correctly advises users to follow established organizational practices, such as obtaining W-9/W-8BEN forms through finance and having counsel review contracts. It does not hardcode any sensitive credentials or exfiltrate data to unauthorized third parties.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user input to generate a brief. While this is an ingestion point for untrusted data, the output is a static markdown document meant for human review and further professional processing. It does not execute commands or network operations based on the generated content, maintaining a safe posture.
  • [COMMAND_EXECUTION]: No shell commands, scripts, or system-level operations are present in the skill instructions or metadata.
  • [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote code. All external references are conceptual or link to internal skill identifiers.
  • [SAFE_PRACTICE]: The instructions explicitly emphasize security and legal best practices, such as IP assignment, confidentiality (NDA) clauses, and data protection agreements when handling customer data.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 07:05 AM
Security Audit — agent-trust-hub — 67-agency-vendor-brief-global