sales-tibco
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill serves as a technical knowledge base for TIBCO Cloud Integration. Analysis of the instructions and reference files reveals no malicious intent or security violations.
- [DATA_EXFILTRATION]: The skill references legitimate, well-known TIBCO service endpoints (e.g.,
api.cloud.tibco.com,eu.api.cloud.tibco.com) and official GitHub repositories under theTIBCOSoftwareorganization. These references are documented for the user's or agent's contextual awareness of the platform and do not involve unauthorized data transit. - [COMMAND_EXECUTION]: The skill includes instructions for using official CLI tools (e.g.,
tibco-cli) and installation commands for related skills from the same vendor (sales-skills). These are standard operational instructions for the documented platform and do not constitute arbitrary or dangerous command execution. - [PROMPT_INJECTION]: A functional surface for indirect prompt injection exists via the instruction to append new insights to
references/learnings.md. This is a standard "persistent memory" pattern for this class of skills. The skill does not contain any direct injection attempts, jailbreaks, or instructions to bypass safety filters. - [REMOTE_CODE_EXECUTION]: References to external repositories and plugins (e.g.,
flogo-maven-plugin) are directed at official vendor sources. No patterns for unverified remote script execution (likecurl | bash) are present.
Audit Metadata