document-inventory

Pass

Audited by Gen Agent Trust Hub on Sep 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute system commands including find, git diff, git log, and Get-ChildItem. These are used for legitimate file discovery and version control delta detection within the workspace.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data which constitutes a vulnerability surface for indirect prompt injection.
  • Ingestion points: The skill receives input paths and processes metadata (title, author, subject, etc.) extracted from external documents (.docx, .xlsx, .pptx, .pdf) as described in SKILL.md.
  • Boundary markers: Absent. The Inventory Request Context and the resulting structured summary do not specify delimiters or instructions to ignore instructions potentially embedded within the file metadata.
  • Capability inventory: The skill uses read-only discovery commands (find, git, Get-ChildItem). It does not possess network exfiltration, file-write, or arbitrary code execution (eval/exec) capabilities.
  • Sanitization: Absent. There is no mention of sanitizing or escaping document properties before they are included in the final inventory report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 26, 2026, 05:59 AM