bid-leveling
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by reading user-provided bid documents in multiple formats including PDF, Word, Excel, and images to extract cost items and contractual terms.
- Ingestion points:
SKILL.md(Step 2: Read Bid Documents). - Boundary markers: No explicit delimiters are defined for the text extraction phase.
- Capability inventory: The skill's capabilities are limited to generating local report files using the provided
generate_csv.pyandgenerate_pdf.pyscripts. No network operations, system persistence, or dangerous command execution vectors were identified. - Sanitization: Data is structured into JSON format before being processed by local generation scripts.
- [SAFE]: No evidence of prompt injection, obfuscation, or credential theft was found. The skill follows standard practices for data analysis and reporting, utilizing established Python packages for document generation.
Audit Metadata