purchase-order-management
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown instructions and YAML templates for business processes. No executable scripts (Python, Shell, JavaScript) are included in the distribution.
- [INDIRECT_PROMPT_INJECTION]: The workflow involves the agent reading and processing data from external, potentially untrusted sources (vendors).
- Ingestion points: Invoices, delivery notes, and vendor acknowledgment communications (identified in Phases 3 and 4).
- Boundary markers: Absent; there are no instructions for the agent to use delimiters or ignore potential instructions embedded within vendor documents.
- Capability inventory: The skill defines a text-based workflow for documentation and tracking but does not include shell access, network operations, or file-write capabilities in its own logic.
- Sanitization: No validation or sanitization requirements are specified for external vendor-provided strings.
Audit Metadata