esign-field-placement

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The workflow involves processing external agreement documents and web page content which could contain untrusted instructions. 1. Ingestion points: Agreement templates (.docx), web composer page content, and counterparty metadata. 2. Boundary markers: The instructions explicitly command the agent to ignore page text, links, or redirects for extending allowlists or authorizing actions. 3. Capability inventory: Browser automation for UI interaction and screenshot capture. 4. Sanitization: Instructions for screenshot naming require opaque identifiers (UUIDs) and the rejection of path separators or control characters.
  • [NO_CODE]: The skill files contain instructional documentation and a checklist only. No executable scripts, binary files, or automated commands are provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 01:58 PM
Security Audit — agent-trust-hub — esign-field-placement