uipath-automation-discovery

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [DATA_EXFILTRATION]: The skill is designed to ingest and analyze highly sensitive enterprise data from HRIS, ERP, CRM, and internal communications. While this is its primary functional purpose, the breadth of access represents a significant data exposure surface. The skill incorporates mitigation rules requiring explicit authorization and the pseudonymization of individuals by default.
  • [PROMPT_INJECTION]: There is a surface for indirect prompt injection because the skill mines untrusted data from Slack, Wikis, Jira, and Email. Malicious instructions embedded in these sources could potentially manipulate the agent's analysis or influence the priority of the resulting automation report. The skill lacks explicit sanitization steps or boundary markers for this ingested content.
  • [COMMAND_EXECUTION]: The documentation references the use of external command-line tools, specifically the Salesforce CLI (sf) and GitHub CLI (gh), to verify system access and query data. These are standard professional tools and their use is consistent with the skill's discovery objectives.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 07:12 PM
Security Audit — agent-trust-hub — uipath-automation-discovery