exposure-risk-quantification
Pass
Audited by Gen Agent Trust Hub on Aug 14, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external reconnaissance findings, which creates a surface where malicious instructions could be embedded in the data being quantified.
- Ingestion points: Processes findings, assets, and metadata collected during reconnaissance passes (documented in SKILL.md §1 and §7).
- Boundary markers: The instructions lack explicit delimiters or guidance for the agent to distinguish between findings data and control instructions, increasing the risk of the agent obeying instructions embedded within processed assets.
- Capability inventory: The skill possesses the capability to curate data, perform complex mathematical calculations, and trigger report rendering (mentioning headless Chromium and Playwright in §10.5).
- Sanitization: There is no mention of sanitization, escaping, or schema validation to ensure that external content is safe before it is interpolated into quantification routines or reports.
Audit Metadata