weekly-report

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious instructions, obfuscation, or data exfiltration patterns were found. The skill operates within the expected scope of a report generator.
  • [SAFE]: The integration with external platforms (Notion, Linear, Asana) is handled through standard tool interfaces (MCP), which is the recommended practice for data access.
  • [SAFE]: The skill instructions proactively advise on data safety by recommending the use of 'moai-legal:nda-triage' for processing confidential information.
  • [SAFE]: A surface for indirect prompt injection exists due to data ingestion from project management tools, but the risk is assessed as safe as the skill's operations are limited to text formatting without dynamic code execution. Ingestion points: Notion/Linear/Asana MCP and file uploads; Boundary markers: Not explicitly defined in prompt templates; Capability inventory: Text and markdown report generation; Sanitization: Recommended use of internal NDA triage skill.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 06:27 AM
Security Audit — agent-trust-hub — weekly-report