space-xhs-note-analytics

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No security issues were detected. The skill is designed for offline data analysis of creator metrics and does not attempt to perform network exfiltration, hardcode credentials, or execute arbitrary shell commands. \n- [PROMPT_INJECTION]: The skill processes user-supplied data files (CSV/Excel), which is an inherent surface for indirect prompt injection. However, the skill implements significant mitigations including a 'probe' phase to inspect file headers before full ingestion and specific 'Honesty Boundaries' that instruct the agent to avoid fabricating conclusions or obeying instructions embedded within the data. The accompanying Python script is limited to read-only statistical analysis, and the skill lacks the capabilities (e.g., network or filesystem writes) necessary for an injection to cause harm.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 05:12 PM
Security Audit — agent-trust-hub — space-xhs-note-analytics