kelly-education-intel

Pass

Audited by Gen Agent Trust Hub on Aug 25, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or security risks were identified. The skill adheres to its documented purpose and safety boundaries.
  • [INDIRECT_PROMPT_INJECTION]: The skill has an attack surface for indirect prompt injection because it ingests untrusted data from public education sources (bureaus, exam boards, competitor sites). However, this is mitigated by a mandatory human-in-the-loop review cockpit. All signals, actions, and drafts must be approved in the UI before they are marked as ready for use. Evidence: Review workflow logic in SKILL.md and education-model.js.
  • [COMMAND_EXECUTION]: The provided utility scripts (execute_decisions.mjs, setup.mjs, publish_airapp.mjs) are used solely for managing database resources and application code within the Busabase environment. They do not execute arbitrary shell commands or interact with the local operating system in a dangerous manner.
  • [DATA_EXFILTRATION]: Network operations are limited to the intended Busabase workspace. The skill does not attempt to send data to third-party analytics, command-and-control servers, or other unauthorized destinations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 25, 2026, 10:36 AM
Security Audit — agent-trust-hub — kelly-education-intel