x-ray-a-company
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill defines a manual procedural workflow and does not contain any executable scripts, remote code downloads, or hidden logic. All referenced external resources (e.g., SEC EDGAR, OFAC, GLEIF) are legitimate government or international organization databases.
- [PROMPT_INJECTION]: The skill processes untrusted data sources like invoices, contracts, and websites, which introduces a surface for indirect prompt injection. Evidence Chain: (1) Ingestion points: Document and website inputs in Step 2; (2) Boundary markers: Absent; (3) Capability inventory: Skill calls to OSINT tools such as who-really-owns-it and find-anyone; (4) Sanitization: Absent. This risk is inherent to the OSINT due diligence process and is considered low as the skill lacks exploitable capabilities.
- [DATA_EXFILTRATION]: No patterns of unauthorized data exfiltration were found. The skill focuses on reading public documents and performing lookups in public registries.
Audit Metadata