cim-builder

Pass

Audited by Gen Agent Trust Hub on Jun 13, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [Indirect Prompt Injection]: The skill is designed to process external inputs such as management presentations, website content, and financial reports to draft the memorandum.
  • Ingestion points: Step 1 (Gather Source Materials) lists several external data sources to be used as context.
  • Boundary markers: The skill does not explicitly specify delimiters or use 'ignore embedded instructions' warnings for the input data.
  • Capability inventory: The skill instructs the agent to draft documents (.docx) and spreadsheets (.xlsx). It does not include subprocess calls, shell execution, or network operations.
  • Sanitization: No explicit sanitization or filtering of the input content is defined in the instructions.
  • [Data Sensitivity Consideration]: The skill guides the collection of highly sensitive business information (financials, customer lists, org charts). It correctly recommends anonymizing sensitive data and including confidentiality disclaimers, which aligns with best practices for handling proprietary information.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 13, 2026, 10:21 AM
Security Audit — agent-trust-hub — cim-builder