hr-business-partner

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external CSV files containing highly sensitive personnel data such as salaries, performance ratings, and demographic information without performing sanitization on text-based fields.
  • Ingestion points: The skill ingests data via scripts/compensation_analyzer.py (reading comp_data.csv), scripts/org_health_scorer.py (reading org_metrics.csv), and scripts/workforce_dashboard.py (reading workforce.csv).
  • Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are present in the workflows to prevent the model from potentially following adversarial instructions embedded within the processed data.
  • Capability inventory: The skill allows the agent to process data and generate reports for leadership. The included scripts do not have network access or file-writing capabilities beyond console output.
  • Sanitization: While numeric and date fields are parsed and validated, several string fields (e.g., department names, job levels, and employee categories) are included in reports without escaping or validation.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:12 PM
Security Audit — agent-trust-hub — hr-business-partner