skills/build-plus/skills/bid-leveling/Gen Agent Trust Hub

bid-leveling

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by reading user-provided bid documents in multiple formats including PDF, Word, Excel, and images to extract cost items and contractual terms.
  • Ingestion points: SKILL.md (Step 2: Read Bid Documents).
  • Boundary markers: No explicit delimiters are defined for the text extraction phase.
  • Capability inventory: The skill's capabilities are limited to generating local report files using the provided generate_csv.py and generate_pdf.py scripts. No network operations, system persistence, or dangerous command execution vectors were identified.
  • Sanitization: Data is structured into JSON format before being processed by local generation scripts.
  • [SAFE]: No evidence of prompt injection, obfuscation, or credential theft was found. The skill follows standard practices for data analysis and reporting, utilizing established Python packages for document generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 01:40 AM
Security Audit — agent-trust-hub — bid-leveling