ito-basket-compare

Pass

Audited by Gen Agent Trust Hub on Jun 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it is instructed to ingest and process untrusted user data from various sources.
  • Ingestion points: User's knowledge base, portfolio notes, research memos, CRM context, watchlists, and holdings summaries as described in SKILL.md.
  • Boundary markers: Absent. The skill lacks instructions to wrap ingested data in delimiters or to disregard embedded instructions within that data.
  • Capability inventory: The skill has read access to sensitive user documents and utilizes a platform-provided API key (ITO_API_KEY) to fetch market data.
  • Sanitization: Absent. There is no mention of filtering, escaping, or validating the content of the processed documents before they are incorporated into the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 16, 2026, 02:47 PM
Security Audit — agent-trust-hub — ito-basket-compare