investigation-open

Pass

Audited by Gen Agent Trust Hub on Jul 3, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill ingests user-provided descriptions of allegations which are then used to initialize an investigation. This creates an indirect prompt injection surface.
  • Ingestion points: User-supplied argument describing the allegation enters the context at runtime.
  • Boundary markers: No explicit delimiters or warnings are found in the instructions to separate user input from agent instructions.
  • Capability inventory: The skill delegates the primary logic to the 'internal-investigation' reference skill; no direct shell execution, file writes, or network calls are present in this specific file.
  • Sanitization: No input validation or sanitization is mentioned for the allegation description before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 3, 2026, 03:58 PM
Security Audit — agent-trust-hub — investigation-open