pricing-audit
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze content from external pricing URLs. This creates a potential surface for indirect prompt injection if the target webpage contains malicious instructions intended to manipulate the agent's audit logic.
- Ingestion points: Live pricing pages retrieved via WebFetch (Workflow step 1).
- Boundary markers: The instructions do not define the use of delimiters or specific warnings to ignore embedded instructions when parsing the external content.
- Capability inventory: The skill possesses Read, Write, and Grep capabilities, which could be leveraged if an injection influenced the agent to perform unauthorized file operations.
- Sanitization: No explicit sanitization, validation, or filtering of the external HTML/text content is specified.
- [SAFE]: The skill follows a legitimate business audit structure based on the JMC 30-Point Pricing Audit framework. The logic for calculating scores and identifying remediation levers is transparent and consistent with its stated purpose. There are no signs of obfuscation, hardcoded credentials, or unauthorized persistence mechanisms.
Audit Metadata