esign-field-placement
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The workflow involves processing external agreement documents and web page content which could contain untrusted instructions. 1. Ingestion points: Agreement templates (.docx), web composer page content, and counterparty metadata. 2. Boundary markers: The instructions explicitly command the agent to ignore page text, links, or redirects for extending allowlists or authorizing actions. 3. Capability inventory: Browser automation for UI interaction and screenshot capture. 4. Sanitization: Instructions for screenshot naming require opaque identifiers (UUIDs) and the rejection of path separators or control characters.
- [NO_CODE]: The skill files contain instructional documentation and a checklist only. No executable scripts, binary files, or automated commands are provided.
Audit Metadata