identity-graph-operator
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and process records from external sources, which introduces a surface for indirect prompt injection.
- Ingestion points: The agent ingests records from potentially untrusted sources for identity resolution (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or warnings to ignore instructions embedded within the ingested data.
- Capability inventory: The skill is restricted to data matching and resolution logic; it does not contain capabilities for system command execution or network exfiltration.
- Sanitization: The skill performs basic field normalization but lacks comprehensive sanitization to protect against malicious instructions in the input data.
Audit Metadata