company-ai-policy
Pass
Audited by Gen Agent Trust Hub on Jun 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface (Category 8) because it is instructed to ingest and process data from untrusted external sources (the target system's files).
- Ingestion points: The skill reads content from
memory/,sources/,agents/, rootCLAUDE.md,module-N/, andskills/directories. - Boundary markers: The instructions do not define clear delimiters (e.g., XML tags or triple backticks) to separate the system files from the agent's instructions, nor do they include warnings to ignore instructions embedded within the audited files.
- Capability inventory: The skill performs extensive file system reads across various directories and writes a detailed report to
module-4/policy-report.md. - Sanitization: There is no evidence of sanitization, escaping, or validation of the content retrieved from the target files before it is processed by the AI.
Audit Metadata