audit-project-usage-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses ae-cli to perform ad-hoc data exports for analysis. These commands are restricted to the platform's analytical functions and do not present a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes project-specific data like report names and user identifiers. While this is an ingestion surface for potentially untrusted data, the risk is negligible as it is used for categorization and display. Evidence Chain: Ingestion points: scripts/generate_report.py reads JSONL files; Boundary markers: Absent; Capability inventory: ae-cli, python3, and local file writing; Sanitization: esc_xml for XML output.
  • [EXTERNAL_DOWNLOADS]: The skill references lark-cli for report integration with Feishu. This is a reference to an official tool for a well-known service and is consistent with the skill's reporting functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 07:20 AM
Security Audit — agent-trust-hub — audit-project-usage-analysis