business-messaging-automation

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [NO_CODE]: This skill consists of markdown logic and instructions for an AI agent and does not include any scripts, binaries, or configuration files.
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface as it is designed to ingest and process external, potentially untrusted data for transmission to mobile channels.
  • Ingestion points: External data sources including revenue reports, invoices, and server error logs as referenced in SKILL.md enter the agent context.
  • Boundary markers: The instructions do not define delimiters or specific warnings to ignore instructions embedded within the ingested data.
  • Capability inventory: The skill describes the use of tools like whatsapp_send_message and channel_search (referenced in SKILL.md) to interact with external messaging platforms.
  • Sanitization: There is no mention of sanitizing, escaping, or validating the content of the ingested reports or logs before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 05:56 PM
Security Audit — agent-trust-hub — business-messaging-automation