due-diligence
Pass
Audited by Gen Agent Trust Hub on Sep 24, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external data, including data-room materials, contracts, customer records, and financial statements. This creates a surface for indirect prompt injection if those documents contain hidden instructions.
- Ingestion points: External files such as "contracts", "customer records", "management accounts", "presentations", and "data-room" documents (identified in SKILL.md and references/commercial-operational.md).
- Boundary markers: The instructions do not specify the use of delimiters or provide warnings to the agent to ignore instructions embedded within the data being analyzed.
- Capability inventory: The skill utilizes standard reasoning and file-reading capabilities; it does not explicitly invoke unsafe subprocesses, network operations, or privileged system commands.
- Sanitization: There are no instructions provided to validate, sanitize, or filter the content of the analyzed documents for malicious prompt injection patterns.
Audit Metadata