collab-vendor

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill references official South Korean government domains (hometax.go.kr and ftc.go.kr) to provide users with tools for verifying business registration status and accessing standard subcontracting agreements. These are well-known services relevant to the skill's domain and do not involve sensitive data harvesting.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze user-supplied vendor data and contract details. While it lacks explicit boundary markers (delimiters) for untrusted data, its capabilities are restricted to document generation and reporting without any dangerous execution paths like shell access or arbitrary network requests, minimizing the threat surface.
  • [SAFE]: No obfuscation, persistence mechanisms, or unauthorized privilege escalation attempts were detected. The skill's logic is consistent with its stated purpose of procurement and risk management, and it correctly references other internal vendor resources (e.g., moai-coworker, moai-writer) for post-processing tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:41 PM
Security Audit — agent-trust-hub — collab-vendor