signals-scout-web-vitals
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFE
Full Analysis
- [PROMPT_INJECTION]: The skill identifies
$hostand$pathnameas attacker-controllable telemetry and provides mandatory SQL sanitization logic using regex filtering and length capping to prevent malicious content from entering the agent context or findings.\n- [DATA_EXFILTRATION]: Data operations are restricted to approved analytics tools (execute-sql) and report generation tools (emit_report) within the platform environment, with no evidence of unauthorized data access or external exfiltration.\n- [COMMAND_EXECUTION]: Database interactions are strictly scoped to telemetry analysis using defined SQL patterns, and all shell-like capabilities are managed through restricted tools.\n- [SAFE]: No obfuscation, persistence mechanisms, or unauthorized privilege escalation patterns were detected in the skill instructions or scripts.
Audit Metadata