document-inventory
Pass
Audited by Gen Agent Trust Hub on Sep 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the agent to execute system commands including
find,git diff,git log, andGet-ChildItem. These are used for legitimate file discovery and version control delta detection within the workspace. - [INDIRECT_PROMPT_INJECTION]: The skill processes external data which constitutes a vulnerability surface for indirect prompt injection.
- Ingestion points: The skill receives input paths and processes metadata (title, author, subject, etc.) extracted from external documents (.docx, .xlsx, .pptx, .pdf) as described in
SKILL.md. - Boundary markers: Absent. The
Inventory Request Contextand the resulting structured summary do not specify delimiters or instructions to ignore instructions potentially embedded within the file metadata. - Capability inventory: The skill uses read-only discovery commands (
find,git,Get-ChildItem). It does not possess network exfiltration, file-write, or arbitrary code execution (eval/exec) capabilities. - Sanitization: Absent. There is no mention of sanitizing or escaping document properties before they are included in the final inventory report.
Audit Metadata