trigger-agents

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill templates demonstrate patterns that ingest untrusted data and incorporate it into LLM prompts without sanitization or robust boundary markers.
  • Ingestion points: The skill processes external inputs such as text in the translateCopy task (SKILL.md), article content in the factChecker task (SKILL.md), url strings in the readUrl tool (references/ai-tool.md), and user question inputs in the routeQuestion task (SKILL.md).
  • Boundary markers: The code examples generally lack specific delimiters or instructions for the LLM to ignore embedded commands within the input data, increasing the risk of the model following malicious instructions contained in processed text.
  • Capability inventory: The tasks have access to powerful capabilities including LLM text generation (generateText), network requests (fetch), and external resource fetching (searchWeb, fetchAndParse).
  • Sanitization: No sanitization, escaping, or validation of the input strings is shown in the provided patterns to mitigate injection attacks.
  • [DATA_EXFILTRATION]: The orchestration patterns include examples of performing network operations using dynamically provided URLs, which could be exploited for exfiltration or SSRF.
  • Evidence: In references/orchestration.md, the callExternalApi task executes fetch(payload.url) using a variable payload. Similarly, in references/ai-tool.md, the read-url tool executes fetchAndParse(url) based on agent-provided input. If an agent is manipulated via prompt injection, these tools could be used to target internal services or exfiltrate sensitive information to external attacker-controlled endpoints.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — trigger-agents