67-agency-vendor-brief-global
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides structured guidance and templates for vendor management, focusing on operational efficiency and risk mitigation through clear documentation.
- [DATA_EXPOSURE]: The template includes placeholders for business contact information (names, emails, phones) and budget details. However, it correctly advises users to follow established organizational practices, such as obtaining W-9/W-8BEN forms through finance and having counsel review contracts. It does not hardcode any sensitive credentials or exfiltrate data to unauthorized third parties.
- [INDIRECT_PROMPT_INJECTION]: The skill processes user input to generate a brief. While this is an ingestion point for untrusted data, the output is a static markdown document meant for human review and further professional processing. It does not execute commands or network operations based on the generated content, maintaining a safe posture.
- [COMMAND_EXECUTION]: No shell commands, scripts, or system-level operations are present in the skill instructions or metadata.
- [REMOTE_CODE_EXECUTION]: There are no patterns involving the download or execution of remote code. All external references are conceptual or link to internal skill identifiers.
- [SAFE_PRACTICE]: The instructions explicitly emphasize security and legal best practices, such as IP assignment, confidentiality (NDA) clauses, and data protection agreements when handling customer data.
Audit Metadata