delivery-manager

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external JSON files which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The scripts delivery_metrics_tracker.py, dependency_mapper.py, and risk_register.py all load and parse user-provided JSON data files via command-line arguments.
  • Boundary markers: The instructions do not provide explicit delimiters or "ignore instructions" wrappers for the content processed from these data files.
  • Capability inventory: The skill's primary capabilities involve processing data and generating reports. No critical capabilities such as arbitrary shell execution or network exfiltration are currently exposed to the data processing pipeline.
  • Sanitization: The scripts use standard JSON parsing but do not perform explicit sanitization or validation of the text content within the JSON fields before presenting them to the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:28 AM
Security Audit — agent-trust-hub — delivery-manager