cowork-data-room-builder
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill performs legitimate file organization and audit tasks within the user's local environment. No suspicious remote code execution or exfiltration attempts were found.
- [DATA_EXPOSURE]: The skill is intended to process sensitive documents such as financials, cap tables, and contracts to build a data room. This behavior is transparently documented as the primary goal of the skill and involves local file operations using Glob, Read, and Write tools.
- [PROMPT_INJECTION]: The skill ingests data from external sources (Step 2: Sweep) which presents a surface for indirect prompt injection if the documents being processed contain malicious instructions. However, this is a common risk for data-processing agents and no active exploit was identified. * Ingestion points: Company document folders (referenced in Step 2). * Boundary markers: None present. * Capability inventory: Bash, Write, Read, Glob, Grep, and WebSearch (listed in tools). * Sanitization: None described.
Audit Metadata