eu-proposal-organisation-assessment

Pass

Audited by Gen Agent Trust Hub on Aug 31, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and analyze external, untrusted proposal documents provided by users.
  • Ingestion points: The skill explicitly requires the user to provide "the proposal document or documents" in SKILL.md.
  • Boundary markers: There are no explicit delimiters (e.g., XML tags or unique markers) defined to isolate untrusted document text from instructions, nor are there specific instructions for the agent to ignore embedded commands within those documents.
  • Capability inventory: The skill is configured to read files and generate complex Markdown reports with Mermaid diagrams. It does not explicitly call network or code execution tools, but it operates in an environment where tools are not restricted by the frontmatter.
  • Sanitization: The skill lacks explicit sanitization or filtering logic for the content ingested from the external documents before it is interpolated into the analysis flow.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 31, 2026, 05:42 PM
Security Audit — agent-trust-hub — eu-proposal-organisation-assessment