ai-agent-team-composition
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a collection of methodology guidelines and templates for project planning. It does not contain any executable scripts, binary files, or automated commands that could pose a security risk.
- [PROMPT_INJECTION]: The skill includes a workflow to process external data sources such as procurement frameworks, CVs, and buyer evidence to generate staffing plans. While this creates an ingestion surface for potential indirect prompt injection, the skill's defined 'Capability Contract' strictly limits the agent to read-only discovery and planning within a proposal context, preventing unauthorized autonomous actions or system modifications.
- [SAFE]: All references within the skill point to local relative file paths within the repository's internal structure. No external network requests or remote resource fetching were identified.
Audit Metadata