mortgage-loan-fallout-premortem

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to process and analyze untrusted external data such as borrower income statements, credit reports, and asset documentation. This creates a surface for indirect prompt injection where instructions embedded in processed documents could attempt to subvert the agent's logic. * Ingestion points: Mortgage file submissions, underwriting documents, and borrower financial records (SKILL.md). * Boundary markers: None identified in the skill instructions. * Capability inventory: None. The skill is instructional and does not provide accompanying scripts or tool definitions. * Sanitization: None identified; the skill assumes direct analysis of provided data.
  • [EXTERNAL_DOWNLOADS]: The skill includes informational links to the author's official website (deciqai.com) and GitHub organization (github.com/deciqai) for extended documentation, examples, and machine-readable metadata. These references target vendor-owned infrastructure.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 08:15 AM
Security Audit — agent-trust-hub — mortgage-loan-fallout-premortem