ito-basket-compare
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection attack surface because it is instructed to ingest and process untrusted user data from various sources.
- Ingestion points: User's knowledge base, portfolio notes, research memos, CRM context, watchlists, and holdings summaries as described in SKILL.md.
- Boundary markers: Absent. The skill lacks instructions to wrap ingested data in delimiters or to disregard embedded instructions within that data.
- Capability inventory: The skill has read access to sensitive user documents and utilizes a platform-provided API key (ITO_API_KEY) to fetch market data.
- Sanitization: Absent. There is no mention of filtering, escaping, or validating the content of the processed documents before they are incorporated into the agent's context.
Audit Metadata