data-import

Pass

Audited by Gen Agent Trust Hub on Apr 29, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes multiple JavaScript snippets for the SN-Execute-Background-Script tool. These are used for administrative tasks such as retrying failed rows, monitoring performance, and rolling back changes.
  • [PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection through data ingestion. Ingestion points: Data sources defined in Phase 1 (File, JDBC, LDAP, REST). Boundary markers: Not specifically defined for data input. Capability inventory: Includes SN-Execute-Background-Script and extensive CRUD operations. Sanitization: Examples in Phase 5.3 (onBefore scripts) demonstrate validation and data normalization techniques.
  • [SAFE]: All external URLs point to official ServiceNow documentation (docs.servicenow.com). Configuration examples for database and REST connections correctly use placeholders like [encrypted_password] for sensitive information.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 29, 2026, 04:36 PM