data-management
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists of instructional guidelines and reference documentation. No executable code, remote script downloads, or obfuscation techniques were identified.\n- [DATA_EXFILTRATION]: The skill references the author's personal website (techguypeter.com). This is consistent with the provided author context for Peter Bamuhigire and is documented as a vendor-owned resource without security concerns.\n- [PROMPT_INJECTION]: The skill processes external data sources such as Terms of Reference (ToR) and system documentation. This represents a standard functional surface for its intended purpose. The skill mitigates risks through explicit instructions to verify data purpose, map flows to stated goals, and maintain a 'least-privilege' read-only stance by default.\n
- Ingestion points: Terms of Reference (ToR), system owner inputs, and client control documents referenced in SKILL.md.\n
- Boundary markers: Instructions explicitly require the agent to 'Stop or block the workflow when a required input... is missing' and to 'mark compliance and quality controls unassessed' if evidence is absent.\n
- Capability inventory: Access is limited to tools for reading and searching local files; editing is explicitly restricted to specific authority boundaries.\n
- Sanitization: Requirement to verify jurisdiction and client policy against authoritative sources rather than relying on model memory.
Audit Metadata