icp-evidence-analysis

Pass

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill's design focuses on structured research and evidence verification. It includes explicit instructions to avoid 'persona fiction,' classify information based on its source (e.g., distinguishing between company-asserted and independent data), and halt processing if data falls outside user permissions or contains unnecessary personal information.- [PROMPT_INJECTION]: The skill ingests untrusted data from external URLs, company descriptions, and provided manifests (SKILL.md), creating a surface for indirect prompt injection. The skill mitigates this through rigorous evidence perimeter requirements and source classification.
  • Ingestion points: Company URLs, user-supplied descriptions, source_manifest.json, and public web pages.
  • Boundary markers: The instructions mandate building an 'evidence perimeter' and categorizing data by publisher provenance to isolate asserted claims from verified behavior.
  • Capability inventory: The skill utilizes web research tools to fetch public pages and produces a structured JSON artifact (icp_hypotheses.json).
  • Sanitization: Includes explicit checks for data permission status and instructions to stop if sources contain private or irrelevant personal data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 30, 2026, 02:09 PM
Security Audit — agent-trust-hub — icp-evidence-analysis