people-report
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [Indirect Prompt Injection Surface]: The skill processes external HR data, creating a potential surface for indirect prompt injection if data fields contain instructional text designed to influence the agent's behavior.
- Ingestion points: Processes data from CSV uploads, manual copy-pasting, or integrated HRIS systems as specified in
SKILL.md. - Boundary markers: No specific delimiters or instruction-isolation guidelines are provided within the prompt context.
- Capability inventory: Capabilities are limited to content generation (formatting reports) and sharing via chat channels if connected; no system execution or arbitrary file modifications are present.
- Sanitization: No data validation or verification steps are explicitly detailed in the markdown file.
Audit Metadata