cim-builder
Pass
Audited by Gen Agent Trust Hub on Jun 13, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [Indirect Prompt Injection]: The skill is designed to process external inputs such as management presentations, website content, and financial reports to draft the memorandum.
- Ingestion points: Step 1 (Gather Source Materials) lists several external data sources to be used as context.
- Boundary markers: The skill does not explicitly specify delimiters or use 'ignore embedded instructions' warnings for the input data.
- Capability inventory: The skill instructs the agent to draft documents (.docx) and spreadsheets (.xlsx). It does not include subprocess calls, shell execution, or network operations.
- Sanitization: No explicit sanitization or filtering of the input content is defined in the instructions.
- [Data Sensitivity Consideration]: The skill guides the collection of highly sensitive business information (financials, customer lists, org charts). It correctly recommends anonymizing sensitive data and including confidentiality disclaimers, which aligns with best practices for handling proprietary information.
Audit Metadata