business-analytics-reporter
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's HTML report template (
assets/report_template.html) fetches the Plotly.js visualization library from a well-known CDN (cdn.plot.ly). This is standard practice for including interactive charts in generated business reports and is considered a safe operation for this service. - [INDIRECT_PROMPT_INJECTION]: The skill processes external CSV files containing business data, which represents a vulnerability surface where malicious instructions embedded in the data could attempt to influence the agent's analysis or report generation.
- Ingestion points: The skill loads data from user-supplied CSV files (e.g.,
business_data.csv,q4_sales.csv) as described in theSKILL.mdworkflow and implemented inscripts/analyze_business_data.py. - Boundary markers: The instructions do not specify the use of delimiters or specific prompts to ensure the agent disregards any natural language instructions found within the data fields.
- Capability inventory: The skill is capable of executing a local Python analysis script, reading/writing files (JSON, HTML, Markdown), and generating natural language summaries based on the analyzed data.
- Sanitization: The Python script validates data types for numeric and date columns (e.g., via
pd.to_datetime), but it does not perform sanitization on text-based fields that might be used for interpretation or included in the final HTML report template.
Audit Metadata