mediation-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted external text (dispute descriptions) which creates a surface for indirect prompt injection.
- Ingestion points:
scripts/dispute_analyzer.pyreads user-provided text through the--inputfile flag or--textcommand-line argument. - Boundary markers: Absent; the script does not wrap input in specific delimiters or instructions to ignore embedded commands.
- Capability inventory: The analysis is restricted to local regex-based extraction in
scripts/dispute_analyzer.pyand arithmetic inscripts/settlement_calculator.py. There are no network operations, subprocess spawns, or file system writes (outside of the user-directed--output) across any provided scripts. - Sanitization: Data is sanitized through strict regular expression filtering that only extracts recognized legal entities, dates, and monetary values, preventing the execution of embedded instructions.
Audit Metadata