x-ray-a-company

Pass

Audited by Gen Agent Trust Hub on Aug 24, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill serves as a procedural guide for corporate research and due diligence. It does not contain any executable code, scripts, or automated network operations that pose a security risk.
  • [EXTERNAL_DOWNLOADS]: The workflow mentions various reputable official and international databases for research purposes, such as SEC EDGAR, OFAC, UN Sanctions list, World Bank debarment list, and national registries. These are recognized, legitimate sources for the intended purpose of corporate vetting and do not constitute a security risk.
  • [COMMAND_EXECUTION]: The skill references several other tools and sub-skills like who-really-owns-it and recon-a-domain-passively. These references are standard for defining a multi-step investigative workflow and do not involve arbitrary or dangerous command execution outside the scope of the research tasks.
  • [PROMPT_INJECTION]: No evidence of prompt injection, role-play overrides, or instructions to bypass safety filters was found in the documentation or the checklists.
  • [DATA_EXFILTRATION]: The skill does not contain instructions to access sensitive local files or to exfiltrate credentials to external locations.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 24, 2026, 12:47 PM
Security Audit — agent-trust-hub — x-ray-a-company