asb-more-or-less
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill includes instructions to ingest and process untrusted data from user-provided URLs and files, which serves as a surface for indirect prompt injection.
- Ingestion points: Phase 1 in SKILL.md instructs the agent to read content from external links and files provided by the user.
- Boundary markers: The instructions do not require the use of delimiters or specific prompts to ignore instructions contained within the external data.
- Capability inventory: The skill utilizes capabilities for reading files, writing to a local document (PRICING-STRATEGY.md), and using search tools.
- Sanitization: There are no requirements for sanitizing or validating retrieved content before processing.
Audit Metadata