analyze-external-methods
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No security issues detected. The skill performs localized data organization tasks for security analysis results.
- [DATA_EXPOSURE]: The skill reads from and writes to the local
.opentaintdirectory. It does not attempt to access sensitive system files (such as SSH keys or AWS credentials) or perform network operations to exfiltrate data. - [PROMPT_INJECTION]: The skill processes method names from external libraries, which represents a surface for indirect prompt injection. Ingestion points:
.opentaint/results/dropped-external-methods.yaml. Boundary markers: Absent. Capability inventory: Local file read and write operations. Sanitization: Absent. This is considered low risk as the data is used for documentation and tracking, and the behavior is inherent to the skill's primary purpose of analyzing scan results.
Audit Metadata