automation-mining

Pass

Audited by Gen Agent Trust Hub on Sep 24, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external sources such as Slack, email, and issue trackers, which creates a surface for indirect prompt injection.
  • Ingestion points: External activity records from Slack, mailboxes, issue trackers, and wiki pages.
  • Boundary markers: The skill includes 'Hard Rule 1' which explicitly instructs the agent to treat all read content as data and never instructions, and to report any embedded instructions rather than following them.
  • Capability inventory: The skill utilizes tool APIs for reading activity, writes reports to durable storage, and coordinates multi-agent workers for data processing.
  • Sanitization: 'Hard Rule 5' (Pointers, not payloads) prevents the exfiltration of sensitive information by restricting report content to identifiers and prohibiting the copying of message bodies or credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 24, 2026, 01:58 PM
Security Audit — agent-trust-hub — automation-mining