cb-analytics-links
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through the ingestion of external data-source configurations.
- Ingestion points: Link configuration JSON for S3, GCS, Azure Blob, and remote Couchbase processed via
create_linkandupdate_link(SKILL.md). - Boundary markers: The instructions do not prescribe the use of delimiters (like triple backticks) or explicit instructions for the agent to ignore any natural language commands embedded within the JSON payloads.
- Capability inventory: The skill utilizes several write-authorized tools, including
create_link,update_link, anddelete_link(SKILL.md). - Sanitization: There are no instructions for validating the structure or content of the configuration objects before they are passed to the underlying tools.
Audit Metadata