facilitation-review
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The core instructions in
SKILL.mddefine a specialized persona for reviewing workshop agendas and session designs. The workflow is restricted to textual analysis and critique without involving sensitive tools or external data exfiltration. - [COMMAND_EXECUTION]: The skill includes Node.js utility scripts (
evals/collect-l1-results.mjsandevals/generate-trigger-report.mjs) used by developers to aggregate and report on evaluation data. - These scripts utilize standard Node.js modules (
node:fs,node:path,node:url) for local file operations. evals/collect-l1-results.mjsaccesses a specific local directory within the user's home path (.cursor/projects/...) to process agent transcripts, which is consistent with the intended development use case.- [PROMPT_INJECTION]: The
pressure-scenarios.mdfile contains test prompts that use common injection prefixes such as "IMPORTANT: This is a real task". These are explicitly used as part of a testing suite to verify the agent's robustness and are not part of the runtime instructions that would manipulate the agent's behavior maliciously. - [DATA_EXPOSURE]: The skill processes user-provided facilitation plans. While it interacts with external content, its capabilities are limited to generating a prioritized critique. It does not possess network access or the ability to write to sensitive system files based on the content of the plans it reviews.
Audit Metadata