hr-workforce-planning

Pass

Audited by Gen Agent Trust Hub on Mar 15, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists exclusively of markdown documentation and prompts designed for HR professional tasks.
  • [PROMPT_INJECTION]: No instructions aimed at overriding agent behavior or bypassing safety filters were detected.
  • [DATA_EXFILTRATION]: No sensitive file access, credential exposure, or network communication patterns were identified.
  • [REMOTE_CODE_EXECUTION]: The skill does not download, install, or execute any external scripts or packages.
  • [INDIRECT_PROMPT_INJECTION]: The skill includes an ingestion surface where user data (e.g., department or organization names) is interpolated into prompts. However, as the skill lacks high-risk capabilities such as file system access or network operations, the exploitation potential is negligible.
  • Ingestion points: User input is used in prompt placeholders across all categories (SKILL.md).
  • Boundary markers: None identified.
  • Capability inventory: No code execution, file writing, or network capabilities are present.
  • Sanitization: No sanitization of user-provided strings is implemented.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 15, 2026, 11:06 AM
Security Audit — agent-trust-hub — hr-workforce-planning