facilitation-review

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The core instructions in SKILL.md define a specialized persona for reviewing workshop agendas and session designs. The workflow is restricted to textual analysis and critique without involving sensitive tools or external data exfiltration.
  • [COMMAND_EXECUTION]: The skill includes Node.js utility scripts (evals/collect-l1-results.mjs and evals/generate-trigger-report.mjs) used by developers to aggregate and report on evaluation data.
  • These scripts utilize standard Node.js modules (node:fs, node:path, node:url) for local file operations.
  • evals/collect-l1-results.mjs accesses a specific local directory within the user's home path (.cursor/projects/...) to process agent transcripts, which is consistent with the intended development use case.
  • [PROMPT_INJECTION]: The pressure-scenarios.md file contains test prompts that use common injection prefixes such as "IMPORTANT: This is a real task". These are explicitly used as part of a testing suite to verify the agent's robustness and are not part of the runtime instructions that would manipulate the agent's behavior maliciously.
  • [DATA_EXPOSURE]: The skill processes user-provided facilitation plans. While it interacts with external content, its capabilities are limited to generating a prioritized critique. It does not possess network access or the ability to write to sensitive system files based on the content of the plans it reviews.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 12:27 PM
Security Audit — agent-trust-hub — facilitation-review