audit-project-usage-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill uses
ae-clito perform ad-hoc data exports for analysis. These commands are restricted to the platform's analytical functions and do not present a security risk. - [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data like report names and user identifiers. While this is an ingestion surface for potentially untrusted data, the risk is negligible as it is used for categorization and display. Evidence Chain: Ingestion points:
scripts/generate_report.pyreads JSONL files; Boundary markers: Absent; Capability inventory:ae-cli,python3, and local file writing; Sanitization:esc_xmlfor XML output. - [EXTERNAL_DOWNLOADS]: The skill references
lark-clifor report integration with Feishu. This is a reference to an official tool for a well-known service and is consistent with the skill's reporting functionality.
Audit Metadata