daily-pulse
Pass
Audited by Gen Agent Trust Hub on Aug 4, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill has an inherent surface for indirect prompt injection due to its reliance on external data streams.\n
- Ingestion points: Data enters the system from POS providers (Square, Toast, Clover, Lightspeed, Shopify), payroll tools (Gusto, ADP), and inventory logs as specified in SKILL.md.\n
- Boundary markers: The skill does not specify delimiters or instructions to ignore potential commands embedded within the input data.\n
- Capability inventory: The agent can generate reports, calculate KPIs, and offer textual business recommendations based on the analyzed data.\n
- Sanitization: No data sanitization or input validation steps are provided to prevent malicious content in data sources from influencing agent behavior.\n- [SAFE]: No evidence of hardcoded credentials, malicious scripts, obfuscation, or unauthorized exfiltration logic was found.
Audit Metadata