signals-scout-general

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious behaviors or security risks were identified. The skill's logic is consistent with its stated purpose as a project monitor and data scout.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes external, untrusted data including error logs, analytics events, and database records via execute-sql. This data could potentially contain malicious instructions. The skill provides clear instructions for the agent to validate all hypotheses with concrete evidence and maintain a high confidence threshold before acting, which serves as a significant mitigating factor.
  • [COMMAND_EXECUTION]: The skill uses execute-sql for project analysis. This tool is part of the provided environment for 'posthog' services and is restricted to the intended data analysis scope.
  • [DATA_EXFILTRATION]: The skill 'emits' signals to a specialized inbox and 'remembers' data in a scratchpad. These operations are performed using specific MCP tools provided by the vendor for internal platform functionality and do not constitute unauthorized data exfiltration.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 01:05 AM
Security Audit — agent-trust-hub — signals-scout-general