build-consulting-evidence-base

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements strong data minimization and privacy protections. It instructs the agent to perform a metadata-only inventory when accessing local folders and requires a purpose-minimized allowlist to exclude sensitive personal, medical, HR, or legal material unless explicitly authorized.
  • [DATA_EXFILTRATION]: The instructions include an explicit security constraint against data leakage: 'Do not upload private files or their contents to external web services.' This directly mitigates the risk of exfiltrating sensitive internal or client data discovered during research.
  • [SAFE]: The skill defines a rigorous evidence verification lifecycle (discovered to decision-eligible). It prevents the agent from relying on potentially deceptive or malicious third-party summaries by requiring the inspection of primary, original sources and independent corroboration for all material claims.
  • [SAFE]: The skill uses structured 'evidence packets' and formal 'research contracts' to define boundaries. These mechanisms ensure that data ingestion is purpose-limited and that the agent remains within authorized research grain and knowledge kinds, reducing the risk of capability abuse.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 10:44 AM
Security Audit — agent-trust-hub — build-consulting-evidence-base