one-initiative-brief
Pass
Audited by Gen Agent Trust Hub on Jul 10, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill operates entirely through a predefined set of MCP tools (such as
create-initiativeandlist-initiatives) which are part of the One Horizon execution environment. No arbitrary command execution or external script downloads are performed. - [SAFE]: Phase 3 (Landscape awareness) includes explicit safety guidelines that mandate obtaining user consent before performing external searches. It also strictly prohibits the use of proprietary names or stealth framing in search queries to prevent data leakage.
- [SAFE]: The skill's primary function is generating structured Markdown documentation. There are no patterns suggesting prompt injection, persistence, or privilege escalation. The document preservation rules ('Preserve each existing media source URL') are focused on maintaining document fidelity.
- [SAFE]: While the skill ingests data from existing initiatives (Category 8: Indirect Prompt Injection surface), its rigid output structure and diagnostic phases provide sufficient boundaries for the intended workflow.
Audit Metadata