team-discover

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill is designed for documentation discovery and information retrieval from local project directories. It does not perform network requests, execute shell commands, or access sensitive user credentials.
  • [INDIRECT_PROMPT_INJECTION]: The skill reads and processes external data from a CDR index and module bodies. This creates a standard surface for indirect prompt injection where instructions embedded in the ingested documentation could influence the agent. However, this is a low-risk behavior typical of retrieval-augmented generation (RAG) tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:01 PM
Security Audit — agent-trust-hub — team-discover