work-agent

Pass

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill allows configuring agents to use the Bash tool for automation. This is an intended platform feature for task execution within the Treasure Work environment.
  • [DATA_EXFILTRATION]: Facilitates Slack notifications and file uploads. The instructions explicitly mandate confirming target Slack channels with the user, ensuring data is only sent to authorized locations.
  • [PROMPT_INJECTION]: Manages agent system prompts and run transcript reviews. While the ingestion of agent outputs to iterate on prompts technically creates an indirect injection surface, it is mitigated by mandatory human-in-the-loop review and structured audit steps. Ingestion: agent run transcripts via chat_read. Boundaries: none. Capability inventory: agent_update, agent_create, Bash. Sanitization: agent-review call in Step 5.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 22, 2026, 04:31 PM
Security Audit — agent-trust-hub — work-agent