distribution-ops
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data regarding products and audiences, creating a potential surface for indirect prompt injection.
- Ingestion points: User-provided descriptions of offers, products, and audience access details in the workflow prompts.
- Boundary markers: Absent; the instructions do not implement delimiters or safety warnings for the agent to ignore instructions embedded within the user data.
- Capability inventory: None; the skill's instructions only define text and JSON output formats and do not invoke tools for file system access, network operations, or shell execution.
- Sanitization: Absent; no validation or escaping mechanisms are described for handling external input.
Audit Metadata