delivery-manager
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from external JSON files which could contain malicious instructions designed to influence the agent's behavior.
- Ingestion points: The scripts
delivery_metrics_tracker.py,dependency_mapper.py, andrisk_register.pyall load and parse user-provided JSON data files via command-line arguments. - Boundary markers: The instructions do not provide explicit delimiters or "ignore instructions" wrappers for the content processed from these data files.
- Capability inventory: The skill's primary capabilities involve processing data and generating reports. No critical capabilities such as arbitrary shell execution or network exfiltration are currently exposed to the data processing pipeline.
- Sanitization: The scripts use standard JSON parsing but do not perform explicit sanitization or validation of the text content within the JSON fields before presenting them to the agent.
Audit Metadata