ai-on-saas-pricing-and-packaging-proposal

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: No behavioral override markers, safety filter bypasses, or instructions to ignore system rules were detected. The language is strictly instructional and focused on the stated business purpose.
  • [DATA_EXFILTRATION]: No sensitive file paths (e.g., .ssh, .env, .aws) or network transmission commands (e.g., curl, wget) are present. The skill operates on user-supplied business data within the workspace.
  • [REMOTE_CODE_EXECUTION]: The skill contains no executable scripts, shell commands, or dynamic code execution patterns. It is a Markdown-based instructional document.
  • [EXTERNAL_DOWNLOADS]: No external package installations (pip, npm) or remote script downloads are referenced. All links are internal relative paths to other repository documentation.
  • [OBFUSCATION]: The file was checked for Base64 encoding, zero-width characters, homoglyphs, and other hiding techniques; no obfuscated content was found.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it ingests external documents like 'tenders' and 'discovery notes'. However, the risk is mitigated as the skill lacks executable capabilities (subprocess calls, file-writes to system paths) to act on malicious instructions beyond text drafting. Boundary markers are present in the form of 'Stop conditions' based on evidence quality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 06:11 AM
Security Audit — agent-trust-hub — ai-on-saas-pricing-and-packaging-proposal