live-data-forensics
Pass
Audited by Gen Agent Trust Hub on Aug 29, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process external data from Amplitude, creating a potential surface for indirect prompt injection.
- Ingestion points: Data is retrieved via
query_amplitude_data,get_amp_user_data, andmanage_amp_eventsas described inSKILL.md. - Boundary markers: The instructions do not provide specific delimiters or ignore-instruction warnings for the data being processed.
- Capability inventory: The agent has the capability to query event data, search for entities, and retrieve detailed user timelines.
- Sanitization: The instructions do not include steps for sanitizing or validating the data returned from the Amplitude API before processing.
Audit Metadata