skills/serac-labs/serac/blast-radius/Gen Agent Trust Hub

blast-radius

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [NO_CODE]: The skill does not contain any executable scripts or code blocks. It consists entirely of documentation and tool definitions for an AI agent platform.
  • [COMMAND_EXECUTION]: The skill defines several tools (e.g., snow_blast_radius_dependents, snow_code_search) but these are platform-provided capabilities scoped to the ServiceNow environment for analysis purposes. No arbitrary shell or system command execution is present.
  • [DATA_EXFILTRATION]: While the skill involves searching through ServiceNow configuration data, it does so within the authorized context of the agent's environment for the purpose of dependency tracing. There are no patterns suggesting the exfiltration of sensitive instance data to external or untrusted domains.
  • [PROMPT_INJECTION]: The instructions provide clear guidance on how the agent should interpret tool results and communicate limitations to the user. There are no attempts to bypass safety filters or override the agent's core behavioral guidelines.
  • [INDIRECT_PROMPT_INJECTION]: The skill documents an attack surface by processing ServiceNow script content, but it does so via static analysis tools. The instructions include mandatory caveats that the agent must display to the user, providing transparency about the limitations of the analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 07:15 PM
Security Audit — agent-trust-hub — blast-radius