coo-advisor

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill instructions and metadata do not contain malicious patterns such as direct prompt injections, data exfiltration, or obfuscation. The functionality is consistent with its stated purpose as a COO advisory tool.
  • [COMMAND_EXECUTION]: The skill references local Python scripts (ops_efficiency_analyzer.py and okr_tracker.py) for operational analysis. These are presented as standard internal tools for the agent to use within its environment.
  • [PROMPT_INJECTION]: The skill features an indirect prompt injection surface as it ingests untrusted data from company-context.md and user-provided inputs. 1. Ingestion points: company-context.md and user descriptions of operational bottlenecks. 2. Boundary markers: Absent. 3. Capability inventory: Execution of local Python scripts and sub-agent invocation via task-based orchestration. 4. Sanitization: Absent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:06 PM
Security Audit — agent-trust-hub — coo-advisor