scorecard-review
Pass
Audited by Gen Agent Trust Hub on Mar 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or unauthorized access patterns were identified. The skill correctly utilizes a dedicated MCP server for its operations.
- [PROMPT_INJECTION]: The skill processes external data, including technical documentation and scorecard metadata from the Harness IDP. This presents a potential surface for indirect prompt injection, where malicious instructions embedded in the catalog data could influence the agent's summary or recommendations. This is a common characteristic of skills that process external content.
- [DATA_EXFILTRATION]: The skill is authorized to access sensitive internal information, such as security vulnerability scores, production readiness metrics, and compliance status. This data exposure is limited to the agent's session and is necessary for the skill's stated purpose of service auditing.
Audit Metadata