buyer-job-intent-analysis

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill processes untrusted external data from multiple sources, which creates a surface for indirect prompt injection attacks. 1. Ingestion points: Reads from icp_hypotheses.json, source_manifest.json, and user-supplied transcripts, queries, reviews, support material, and public market sources. 2. Boundary markers: Absent. The instructions do not specify the use of delimiters or 'ignore embedded instructions' warnings for the external data being processed. 3. Capability inventory: The skill reads local files, performs market research, and writes structured Markdown and JSON reports. It does not possess high-risk capabilities like arbitrary command execution or system-level network exfiltration. 4. Sanitization: Partially present via an evidence grading system (A-D) and source-ID linking for provenance, but no specific methods for escaping or filtering the content of external source-language samples are specified before the agent processes them.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 02:09 PM
Security Audit — agent-trust-hub — buyer-job-intent-analysis