trends-bridge

Pass

Audited by Gen Agent Trust Hub on Jul 25, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface because it reads and processes data from external project files to generate new content or enrich existing portfolio entities.
  • Ingestion points: The skill ingests data from multiple JSON files located in the portfolio/ and tips/ directories (e.g., tips-value-model.json, portfolio.json, and market customer files).
  • Boundary markers: The instructions do not specify the use of delimiters or protective markers (e.g., "ignore embedded instructions") when the agent interpolates source text into generated propositions or evidence.
  • Capability inventory: The skill possesses the ability to read, write, and edit files within the project environment using the Read, Write, Edit, Glob, and Grep tools.
  • Sanitization: There is no evidence of explicit sanitization or validation of input strings read from project files before they are utilized for content generation or modification.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 25, 2026, 01:51 PM
Security Audit — agent-trust-hub — trends-bridge