signals-scout-general
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behaviors or security risks were identified. The skill's logic is consistent with its stated purpose as a project monitor and data scout.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it processes external, untrusted data including error logs, analytics events, and database records via
execute-sql. This data could potentially contain malicious instructions. The skill provides clear instructions for the agent to validate all hypotheses with concrete evidence and maintain a high confidence threshold before acting, which serves as a significant mitigating factor. - [COMMAND_EXECUTION]: The skill uses
execute-sqlfor project analysis. This tool is part of the provided environment for 'posthog' services and is restricted to the intended data analysis scope. - [DATA_EXFILTRATION]: The skill 'emits' signals to a specialized inbox and 'remembers' data in a scratchpad. These operations are performed using specific MCP tools provided by the vendor for internal platform functionality and do not constitute unauthorized data exfiltration.
Audit Metadata