workplace-risk-scoring

Pass

Audited by Gen Agent Trust Hub on Mar 23, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXPOSURE]: The skill analyzes the current project's codebase and data structures related to hazard identification, Job Hazard Analysis (JHA), and exposure monitoring. This data access is aligned with its stated purpose as a safety analyst.
  • [COMMAND_EXECUTION]: The skill produces a report in the docs/ directory and recommends the user run other specific audit commands (e.g., /incident-tracking). It does not execute these commands itself.
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it ingests untrusted data from the codebase and user arguments ($ARGUMENTS). It lacks explicit boundary markers or sanitization logic for this content.
  • Ingestion points: Project codebase and user-supplied arguments.
  • Boundary markers: None present.
  • Capability inventory: Read files across the project; Write files to docs/ and ~/.claude/projects/.
  • Sanitization: No escaping or validation of ingested content is specified.
  • [SAFE]: The skill performs no network operations, includes no remote code downloads, and does not attempt to escalate privileges. Its telemetry logging to ~/.claude/projects/ is a localized persistence mechanism for execution metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 23, 2026, 10:58 AM
Security Audit — agent-trust-hub — workplace-risk-scoring