add-teams

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • Command Execution: The skill uses the Bash tool to execute pa app add data-source and npm run build. These operations are standard for Power Platform development and building project assets. The commands are used for their intended purpose within a development environment.
  • Indirect Prompt Injection: The skill is designed to read and update project files such as memory-bank.md and generated service definitions in src/generated/services/. While reading external project files can theoretically introduce untrusted data into the agent's context, this is a standard requirement for development tasks to maintain state and inspect codebases.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 10:15 AM
Security Audit — agent-trust-hub — add-teams