formula-audit-checker
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-provided inputs including Excel model descriptions and known issues, which could be used to pass malicious instructions to the agent.
- Ingestion points: Inputs section in SKILL.md.
- Boundary markers: None identified; user-provided data is not delimited from agent instructions.
- Capability inventory: None; the skill generates text-based checklists and does not execute tools, scripts, or network requests.
- Sanitization: None provided for external inputs.
- [NO_CODE]: The skill does not provide or execute any scripts, binaries, or platform-level tool configurations, significantly limiting the impact of any potential prompt-based attacks.
Audit Metadata