guidewire-core-workflow-a

Pass

Audited by Gen Agent Trust Hub on Mar 14, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill follows standard enterprise integration patterns for Guidewire software and does not exhibit any signs of malicious intent or hidden code.\n- [DATA_EXPOSURE]: The skill documentation describes the handling of sensitive Personal Identifiable Information (PII) such as names, dates of birth, and driver's license numbers. It correctly identifies API credentials as external prerequisites and avoids hardcoding secrets.\n- [INDIRECT_PROMPT_INJECTION]: The skill provides an interface for processing user-supplied data into structured insurance workflows, which represents a potential attack surface.\n
  • Ingestion points: AccountHolderData, VehicleData, and DriverData objects in the SKILL.md code snippets.\n
  • Boundary markers: None identified within the provided logic.\n
  • Capability inventory: The skill is permitted to use Bash(curl:*) for API requests and Write/Edit for file manipulation.\n
  • Sanitization: No explicit sanitization or validation of the input data is demonstrated in the provided code snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 14, 2026, 03:56 AM