signals-scout-revenue-analytics

Pass

Audited by Gen Agent Trust Hub on Aug 4, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill instructions define a specialized monitoring role with clear operational boundaries. It uses platform-provided tools for orientation, data exploration, and reporting within a scoped environment.
  • [PROMPT_INJECTION]: The skill processes untrusted external data, creating a potential surface for indirect injection.
  • Ingestion points: The agent context receives untrusted data from external-data-sync-logs (error patterns) and external-data-sources-retrieve (error strings) as described in SKILL.md.
  • Boundary markers: No explicit delimiters or instructions to ignore embedded commands are present in the guidelines for handling external data.
  • Capability inventory: The skill utilizes execute-sql for database queries, scout-scratchpad-remember for persistent memory, and scout-emit-report/scout-edit-report for outputting findings, as specified in SKILL.md.
  • Sanitization: The instructions do not define specific sanitization or filtering protocols for external content before it is used in downstream tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 4, 2026, 12:28 PM
Security Audit — agent-trust-hub — signals-scout-revenue-analytics