commercial-skills
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted external documents from the workspace, which could contain adversarial instructions aimed at biasing the agent's commercial recommendations.
- Ingestion points: The skill explicitly searches for and ingests RFP PDFs, pipeline exports (CSV), and MSA redlines within the user workspace.
- Boundary markers: There are no explicit delimiters or instructions to ignore embedded commands provided in the skill text to protect the processing of these documents.
- Capability inventory: The orchestrator performs file discovery, routes data to sub-skills, and generates summarized commercial digests; it does not utilize network or shell tools in the analyzed code.
- Sanitization: The instructions lack defined mechanisms for validating or sanitizing the content extracted from external business documents before it is processed.
Audit Metadata