trigger-agents
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill templates demonstrate patterns that ingest untrusted data and incorporate it into LLM prompts without sanitization or robust boundary markers.
- Ingestion points: The skill processes external inputs such as
textin thetranslateCopytask (SKILL.md),articlecontent in thefactCheckertask (SKILL.md),urlstrings in thereadUrltool (references/ai-tool.md), and userquestioninputs in therouteQuestiontask (SKILL.md). - Boundary markers: The code examples generally lack specific delimiters or instructions for the LLM to ignore embedded commands within the input data, increasing the risk of the model following malicious instructions contained in processed text.
- Capability inventory: The tasks have access to powerful capabilities including LLM text generation (
generateText), network requests (fetch), and external resource fetching (searchWeb,fetchAndParse). - Sanitization: No sanitization, escaping, or validation of the input strings is shown in the provided patterns to mitigate injection attacks.
- [DATA_EXFILTRATION]: The orchestration patterns include examples of performing network operations using dynamically provided URLs, which could be exploited for exfiltration or SSRF.
- Evidence: In
references/orchestration.md, thecallExternalApitask executesfetch(payload.url)using a variable payload. Similarly, inreferences/ai-tool.md, theread-urltool executesfetchAndParse(url)based on agent-provided input. If an agent is manipulated via prompt injection, these tools could be used to target internal services or exfiltrate sensitive information to external attacker-controlled endpoints.
Audit Metadata