signature-request

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to ingest and process content from external documents such as PDF or DOCX files and cloud storage links. This data ingestion presents a surface where untrusted content could potentially contain instructions aimed at influencing the agent's behavior.
  • Ingestion points: As described in Step 1, the skill accepts file uploads, URLs, and references to documents.
  • Boundary markers: The skill instructions do not explicitly define delimiters or provide specific prompts for the agent to ignore instructions that might be embedded within the documents being processed.
  • Capability inventory: The skill utilizes integrated tools for electronic signatures and document management to route files and send communications.
  • Sanitization: There is no explicit content validation or sanitization step for the text extracted from documents prior to configuring the signature request.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:27 PM
Security Audit — agent-trust-hub — signature-request