hr-business-partner
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external CSV files containing highly sensitive personnel data such as salaries, performance ratings, and demographic information without performing sanitization on text-based fields.
- Ingestion points: The skill ingests data via
scripts/compensation_analyzer.py(readingcomp_data.csv),scripts/org_health_scorer.py(readingorg_metrics.csv), andscripts/workforce_dashboard.py(readingworkforce.csv). - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are present in the workflows to prevent the model from potentially following adversarial instructions embedded within the processed data.
- Capability inventory: The skill allows the agent to process data and generate reports for leadership. The included scripts do not have network access or file-writing capabilities beyond console output.
- Sanitization: While numeric and date fields are parsed and validated, several string fields (e.g., department names, job levels, and employee categories) are included in reports without escaping or validation.
Audit Metadata