d365-asbuilt
Pass
Audited by Gen Agent Trust Hub on Jun 29, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides a highly structured workflow for technical documentation generation. It lacks any high-risk capabilities such as network access, arbitrary code execution, or administrative privilege requests.
- [COMMAND_EXECUTION]: Analysis of the skill instructions and referenced specifications confirms there are no requests to execute shell scripts, system utilities, or subprocesses.
- [DATA_EXFILTRATION]: No network-bound tools or operations (e.g., curl, wget) are utilized. The skill processes local metadata artifacts solely for the purpose of generating the requested documentation for the user.
- [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection via the ingestion of external solution metadata, but the lack of executable tools mitigates the associated risk.
- Ingestion points: Extracted unmanaged solution metadata folder identified in SKILL.md.
- Boundary markers: Absent; no specific delimiters or instructions to ignore embedded prompts within metadata are provided.
- Capability inventory: Operations are limited to text analysis and DOCX/SVG generation; no network, file-write, or subprocess capabilities are present in the instructions.
- Sanitization: No explicit sanitization or filtering of metadata content is performed before processing.
Audit Metadata