kpi-reporting

Pass

Audited by Gen Agent Trust Hub on Jul 15, 2026

Risk Level: SAFE
Full Analysis
  • Data Source Discovery: The skill is designed to discover and query business data from connected sources, including databases and documentation. This exploration is targeted at establishing an accurate metric framework.
  • Orchestrated Toolset: It utilizes a set of internal tools for data quality analysis, visualization, and reporting (e.g., $build-report, $visualize-data). These tools help process and validate business evidence.
  • Indirect Prompt Injection Surface: The skill ingests data from external sources such as team communications and documents. This creates a surface where the agent processes content that could potentially include unintended instructions, which is a common characteristic of data-driven agents.
  • Ingestion points: Data is pulled from ~~company_docs and ~~team_communication as part of the context-gathering process.
  • Boundary markers: The instructions do not specify the use of specific markers or delimiters to separate ingested data from system instructions.
  • Capability inventory: The skill can invoke reporting and presentation tools like $build-report and $report-to-google-slides.
  • Sanitization: No specific filtering or validation mechanisms for the content of ingested communications are detailed in the skill's instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 15, 2026, 02:41 AM
Security Audit — agent-trust-hub — kpi-reporting