manage-report-lifecycle

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill creates a surface for indirect prompt injection due to its document consolidation workflow.
  • Ingestion points: As described in SKILL.md Phase 1, the agent fetches "rendered content" and "evidence URLs" from external "source reports" and "canonical candidates."
  • Boundary markers: The instructions lack explicit requirements for using delimiters or boundary markers to encapsulate the ingested data, nor do they instruct the model to ignore potential instructions embedded within the fetched report content.
  • Capability inventory: The skill performs write operations to "hosted analytical artifacts" (SKILL.md Phase 4) and invokes external tools including preflight-mutations (Phase 3) and done (Phase 5).
  • Sanitization: The skill explicitly mandates that the agent "preserve the original body and attributed evidence byte-for-byte" (SKILL.md Phase 2), which effectively prevents the agent from sanitizing or filtering potential malicious payloads or instructions contained within the source data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 09:35 AM
Security Audit — agent-trust-hub — manage-report-lifecycle