discover-opportunity

Pass

Audited by Gen Agent Trust Hub on Aug 5, 2026

Risk Level: SAFE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze external user data including code repositories, commit histories, notes, and published writings. While this creates a surface area for indirect prompt injection, the skill lacks associated high-risk capabilities such as file writing, command execution, or network operations within its own scope. Findings are limited to a description of the attack surface.
  • Ingestion points: Processes user-provided repositories, session records, and notes through the conversational context.
  • Boundary markers: The instructions explicitly mandate 'Agree on scope before reading anything personal,' serving as a conceptual boundary for data access.
  • Capability inventory: No subprocess calls, network operations, or privileged tool usage are defined in the configuration.
  • Sanitization: No specific technical sanitization or delimiter strategies are detailed for the model to handle external content.
  • [DATA_EXPOSURE]: The skill's primary function involves accessing sensitive user information (traces, notes, commits). However, it includes explicit instructions to seek user consent and define scope before processing this data. There are no patterns suggesting data exfiltration or hardcoded credentials.
  • [REMOTE_CODE_EXECUTION]: No remote code execution patterns, package installations, or external script downloads were detected in the skill instructions or configuration.
  • [COMMAND_EXECUTION]: The skill does not perform shell command execution or utilize dynamic context injection patterns.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 5, 2026, 06:04 AM
Security Audit — agent-trust-hub — discover-opportunity