work-agent
Pass
Audited by Gen Agent Trust Hub on Jun 22, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill allows configuring agents to use the Bash tool for automation. This is an intended platform feature for task execution within the Treasure Work environment.
- [DATA_EXFILTRATION]: Facilitates Slack notifications and file uploads. The instructions explicitly mandate confirming target Slack channels with the user, ensuring data is only sent to authorized locations.
- [PROMPT_INJECTION]: Manages agent system prompts and run transcript reviews. While the ingestion of agent outputs to iterate on prompts technically creates an indirect injection surface, it is mitigated by mandatory human-in-the-loop review and structured audit steps. Ingestion: agent run transcripts via chat_read. Boundaries: none. Capability inventory: agent_update, agent_create, Bash. Sanitization: agent-review call in Step 5.
Audit Metadata