org-health-diagnostic

Pass

Audited by Gen Agent Trust Hub on Apr 5, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill documentation references a bundled Python script (scripts/health_scorer.py) used for scoring metrics. This is a standard functional component for this type of diagnostic tool and is considered a legitimate vendor resource.
  • [DATA_EXFILTRATION]: The skill is designed to process highly sensitive business metrics such as runway, burn rates, and employee attrition. Analysis confirmed there are no instructions or code patterns suggesting this data is transmitted to unauthorized external endpoints.
  • [PROMPT_INJECTION]: The skill ingests untrusted user data (metrics, company context) which is interpolated into sub-agent tasks. Evidence chain: 1) Ingestion points: User-provided metrics in README.md and SKILL.md; 2) Boundary markers: Absent; 3) Capability inventory: Local script execution and sub-agent orchestration; 4) Sanitization: No explicit data validation or escaping is documented. These behaviors are aligned with the skill's primary analytical purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 5, 2026, 08:05 PM
Security Audit — agent-trust-hub — org-health-diagnostic