hr-ops

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on extensive file system read operations to audit HRIS architecture, organizational structures, and codebase configurations. These operations are necessary for its intended use case of analyzing HR operations but involve accessing sensitive data points such as compensation records and system modules.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests and processes untrusted data from the codebase and HR system records without programmatic sanitization.
  • Ingestion points: System configurations, HR data structures, and the codebase files being analyzed (SKILL.md).
  • Boundary markers: Absent; the skill does not use delimiters to isolate external data from the agent's core instructions.
  • Capability inventory: File system read access and organizational mapping across the environment.
  • Sanitization: Absent; the skill relies on natural language "DO NOT" constraints rather than technical escaping or validation of the ingested content.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:57 AM
Security Audit — agent-trust-hub — hr-ops