jefe-restaurant-online-sales

Pass

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by design, as it is instructed to ingest and process data from external guides.
  • Ingestion points: The skill retrieves content from external sources via the search_jefe_guides and get_jefe_guide tools.
  • Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between its system instructions and the content retrieved from external sources.
  • Capability inventory: The skill definitions are restricted to informational retrieval; no file writing, shell execution, or unauthorized network operations were identified.
  • Sanitization: The skill lacks explicit instructions for sanitizing or validating the integrity of the data returned by the external tools before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 22, 2026, 04:10 PM
Security Audit — agent-trust-hub — jefe-restaurant-online-sales