update-fidelity-recuring

Pass

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through the ingestion of external data from Fidelity and Google Sheets.\n
  • Ingestion points: The agent is instructed to read data from Fidelity's recurring activity webpage and a specific Google Sheet tab.\n
  • Boundary markers: The instructions do not provide delimiters or specific guidance to ignore or isolate instructions that may be embedded in the external content.\n
  • Capability inventory: The skill utilizes the chrome-use library for browser automation and performs data writing operations to Google Sheets.\n
  • Sanitization: There is no evidence of validation or sanitization of the content retrieved from the external sources before it is processed.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 20, 2026, 02:22 PM
Security Audit — agent-trust-hub — update-fidelity-recuring