enterprise-signal-listener

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists entirely of markdown instructions and does not include any executable scripts, binary files, or configuration files that could pose a security risk.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted natural conversation data to extract business signals.
  • Ingestion points: Processes natural language dialogue from users or stakeholders.
  • Boundary markers: The instructions do not define specific delimiters to separate conversation data from the agent's internal logic, though it acts as a passive observer.
  • Capability inventory: None. The skill does not perform any network operations, file system access, or command execution. It only generates YAML output.
  • Sanitization: No explicit sanitization of the input text is mentioned.
  • Risk Assessment: Since the skill has no dangerous capabilities, the risk of indirect prompt injection leading to system compromise is negligible.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 06:13 AM