ai-usage-policy
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill is entirely composed of text-based instructions and does not include scripts, executables, or commands that interact with the host system. It defines a template and methodology for drafting a policy document.
- [DATA_EXPOSURE]: While the skill asks the agent to request information about sensitive data classes (PII, PHI, source code) to help draft the policy, it does not include instructions to automatically read local files or exfiltrate any data to external URLs. It explicitly labels credentials and regulated data as categories that should never be placed in AI tools.
- [PROMPT_INJECTION]: The instructions do not contain patterns for bypassing safety filters, overriding system prompts, or ignoring prior instructions. The use of emphasis (e.g., 'IMPORTANT') is limited to benign instructional guidance.
- [REMOTE_CODE_EXECUTION]: There are no references to external scripts, package managers (npm/pip), or remote code downloads. The skill is standalone and prompt-driven.
- [OBFUSCATION]: The content is written in clear, plain-text Markdown without the use of Base64, hidden characters, or homoglyph-based evasion techniques.
Audit Metadata