bid-analysis
Pass
Audited by Gen Agent Trust Hub on Jul 5, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill performs legitimate document parsing and report generation as described in its metadata. All file operations are localized to the user's provided input.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted data from external documents. However, it incorporates strong defensive instructions—such as requiring verbatim quotes and forbidding data fabrication—which mitigate the risk. * Ingestion points: .pdf, .docx, .doc, .xlsx files (SKILL.md) * Boundary markers: Absent * Capability inventory: File reading and local file writing (SKILL.md) * Sanitization: Absent
Audit Metadata