asb-more-or-less

Pass

Audited by Gen Agent Trust Hub on Aug 16, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill includes instructions to ingest and process untrusted data from user-provided URLs and files, which serves as a surface for indirect prompt injection.
  • Ingestion points: Phase 1 in SKILL.md instructs the agent to read content from external links and files provided by the user.
  • Boundary markers: The instructions do not require the use of delimiters or specific prompts to ignore instructions contained within the external data.
  • Capability inventory: The skill utilizes capabilities for reading files, writing to a local document (PRICING-STRATEGY.md), and using search tools.
  • Sanitization: There are no requirements for sanitizing or validating retrieved content before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 16, 2026, 11:40 PM
Security Audit — agent-trust-hub — asb-more-or-less