so-what
Pass
Audited by Gen Agent Trust Hub on Oct 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill operates on 'the preceding answer', creating an ingestion point for data that might contain instructions from external sources. If the previous response included data from a website or untrusted file, an attacker could attempt to influence the 'practical conclusion' or 'next action' generated by this skill.
- Ingestion points: The conversation context ('preceding answer').
- Boundary markers: None present in the instructions to delimit the untrusted content.
- Capability inventory: Implied tool execution capabilities based on the instruction to 'Carry it out [the next action] only when already authorized'.
- Sanitization: No sanitization or validation of the input context is specified.
Audit Metadata