cb-analytics-links

Pass

Audited by Gen Agent Trust Hub on Jun 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface through the ingestion of external data-source configurations.
  • Ingestion points: Link configuration JSON for S3, GCS, Azure Blob, and remote Couchbase processed via create_link and update_link (SKILL.md).
  • Boundary markers: The instructions do not prescribe the use of delimiters (like triple backticks) or explicit instructions for the agent to ignore any natural language commands embedded within the JSON payloads.
  • Capability inventory: The skill utilizes several write-authorized tools, including create_link, update_link, and delete_link (SKILL.md).
  • Sanitization: There are no instructions for validating the structure or content of the configuration objects before they are passed to the underlying tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 17, 2026, 02:52 AM
Security Audit — agent-trust-hub — cb-analytics-links