vilkaar-med-grunnlag-og-varsling

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a template for software development within the Navikt ecosystem. All activities described are standard practices for building and testing Java-based microservices.
  • [REMOTE_CODE_EXECUTION]: The skill includes instructions to build local internal dependencies using Maven (e.g., cd k9-format && mvn install). These are routine development tasks intended to be executed in a trusted developer environment and do not involve remote code execution from untrusted sources.
  • [DATA_EXFILTRATION]: No patterns indicative of data exfiltration were found. The skill does not access sensitive system files or credentials, and it does not perform network operations to external, non-whitelisted domains.
  • [INDIRECT_PROMPT_INJECTION]: The skill utilizes the ask_user pattern to collect configuration parameters (like condition names and codes) for code generation. This is an intended feature of the skill with no evidence of high-risk capabilities like writing to sensitive system directories or network exfiltration.
  • [OBFUSCATION]: The content is clear and uses standard technical terminology. No hidden text, encoded payloads, or homoglyph attacks were detected.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 11:06 AM
Security Audit — agent-trust-hub — vilkaar-med-grunnlag-og-varsling