kelly-education-intel
Pass
Audited by Gen Agent Trust Hub on Aug 25, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security risks were identified. The skill adheres to its documented purpose and safety boundaries.
- [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests untrusted data from public education sources (bureaus, exam boards, competitor sites). However, this is mitigated by a mandatory human-in-the-loop review cockpit. All signals, actions, and drafts must be approved in the UI before they are marked as ready for use. Evidence: Review workflow logic in
SKILL.mdandeducation-model.js. - [COMMAND_EXECUTION]: The provided utility scripts (
execute_decisions.mjs,setup.mjs,publish_airapp.mjs) are used solely for managing database resources and application code within the Busabase environment. They do not execute arbitrary shell commands or interact with the local operating system in a dangerous manner. - [DATA_EXFILTRATION]: Network operations are limited to the intended Busabase workspace. The skill does not attempt to send data to third-party analytics, command-and-control servers, or other unauthorized destinations.
Audit Metadata