cost-optimization-report
Pass
Audited by Gen Agent Trust Hub on Apr 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted metadata from cloud provider environments, creating a surface for Indirect Prompt Injection.
- Ingestion points: The workflow involves reading resource names, tags, and descriptions from cloud provider APIs (SKILL.md, Steps 2-7).
- Boundary markers: The prompt does not utilize delimiters or specific instructions to isolate these external data values from the agent's logic.
- Capability inventory: In Step 8, the skill instructs the agent to generate specific remediation commands or actions for the user.
- Sanitization: There is no requirement for the agent to sanitize or validate resource metadata before incorporating it into the final report or suggested commands.
- Risk: An attacker with control over cloud resource metadata could inject payloads that influence the remediation advice or commands presented to the user.
Audit Metadata