record-work-history

Pass

Audited by Gen Agent Trust Hub on Jun 15, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill implements a confirmation-based decision workflow that prevents the agent from writing to the filesystem when Material ambiguity regarding project, state, or destination exists.
  • [SAFE]: The instructions include explicit privacy and safety constraints, forbidding the storage of credentials, medical data, or private contact information, and prohibiting destructive system actions or external reporting.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface Analysis: (1) Ingestion points: The skill processes user-provided updates and reads metadata from existing files in the ai-workspace directory. (2) Boundary markers: No explicit delimiters are used to wrap ingested data. (3) Capability inventory: The agent has filesystem read and write access via the agent_mcp tool. (4) Sanitization: The skill relies on its classification logic and human-in-the-loop confirmation to mitigate injection risks.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 15, 2026, 09:37 AM
Security Audit — agent-trust-hub — record-work-history