unified-notifications-ops
Pass
Audited by Gen Agent Trust Hub on Jul 1, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external notification sources such as GitHub, Linear, and local hooks (ingestion point). While it lacks explicit boundary markers for this data, it provides a structured logic for classification and routing that minimizes the risk of the agent following embedded instructions. No executable capabilities or scripts were detected in the skill to exploit this surface.
- [DATA_EXFILTRATION]: The skill defines a non-negotiable security rule: "never expose tokens, secrets, webhook secrets, or internal identifiers." This instruction helps prevent the accidental disclosure of credentials during the notification processing workflow.
- [NO_CODE]: The skill consists entirely of markdown instructions (SKILL.md) and does not contain any executable scripts, shell commands, or dependency configuration files.
Audit Metadata