jefe-restaurant-online-sales
Pass
Audited by Gen Agent Trust Hub on Aug 22, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill possesses a surface for indirect prompt injection by design, as it is instructed to ingest and process data from external guides.
- Ingestion points: The skill retrieves content from external sources via the search_jefe_guides and get_jefe_guide tools.
- Boundary markers: There are no explicit instructions or delimiters provided to the agent to distinguish between its system instructions and the content retrieved from external sources.
- Capability inventory: The skill definitions are restricted to informational retrieval; no file writing, shell execution, or unauthorized network operations were identified.
- Sanitization: The skill lacks explicit instructions for sanitizing or validating the integrity of the data returned by the external tools before it is processed by the agent.
Audit Metadata