d365-asbuilt

Pass

Audited by Gen Agent Trust Hub on Jun 29, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill provides a highly structured workflow for technical documentation generation. It lacks any high-risk capabilities such as network access, arbitrary code execution, or administrative privilege requests.
  • [COMMAND_EXECUTION]: Analysis of the skill instructions and referenced specifications confirms there are no requests to execute shell scripts, system utilities, or subprocesses.
  • [DATA_EXFILTRATION]: No network-bound tools or operations (e.g., curl, wget) are utilized. The skill processes local metadata artifacts solely for the purpose of generating the requested documentation for the user.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection via the ingestion of external solution metadata, but the lack of executable tools mitigates the associated risk.
  • Ingestion points: Extracted unmanaged solution metadata folder identified in SKILL.md.
  • Boundary markers: Absent; no specific delimiters or instructions to ignore embedded prompts within metadata are provided.
  • Capability inventory: Operations are limited to text analysis and DOCX/SVG generation; no network, file-write, or subprocess capabilities are present in the instructions.
  • Sanitization: No explicit sanitization or filtering of metadata content is performed before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 29, 2026, 10:51 AM
Security Audit — agent-trust-hub — d365-asbuilt