bezalel-plane
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from an external MCP server into the agent's context. Content provided by the server, such as tool descriptions or responses from the
health__checktool, could potentially influence agent behavior. - Ingestion points: Data returned from the Bezalel MCP server (e.g.,
http://localhost:3020/mcp) as described in SKILL.md. - Boundary markers: No specific delimiters or warnings for the agent to ignore instructions embedded in server output are provided in the skill instructions.
- Capability inventory: The skill allows the agent to call tools within capability domains such as
financeandcardsbased on the scopes provided in the authentication token. - Sanitization: The skill relies on the underlying agent platform's MCP implementation for sanitizing content received from the server.
Audit Metadata