saas-implementation-methodology

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of instructional text for generating proposal documentation. No executable code, remote script downloads, or unauthorized network operations are present.- [PROMPT_INJECTION]: The instructions include 'Stop conditions' and 'Recovery' steps designed to ensure accuracy and prevent the agent from making fabricated claims. These are safety-reinforcing instructions that guide the agent's behavior within the expected scope rather than attempting to bypass safety filters.- [DATA_EXFILTRATION]: The skill includes a 'Capability and Permission Boundaries' section that explicitly prohibits the agent from sending data, publishing content, or disclosing confidential evidence without explicit authority. No code patterns for data harvesting or exfiltration were found.- [PROMPT_INJECTION]: The skill is designed to ingest external documents such as RFPs and Terms of Reference. While this is an ingestion of untrusted data (Indirect Prompt Injection surface), the risk is assessed as safe because the skill's capabilities are restricted to drafting text within a workspace and it lacks the ability to execute commands or communicate externally.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 06:11 AM
Security Audit — agent-trust-hub — saas-implementation-methodology