skills/erphq/skills/vendor-management/Gen Agent Trust Hub

vendor-management

Pass

Audited by Gen Agent Trust Hub on Jul 6, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists entirely of descriptive Markdown documentation. It contains no executable code, scripts, or binary assets, and does not perform any autonomous actions.\n- [PROMPT_INJECTION]: The skill describes workflows involving the ingestion of external data such as vendor emails, invoices, and news feeds. This constitutes a surface for indirect prompt injection if the skill is implemented without adequate data sanitization.\n
  • Ingestion points: Vendor information from invoices, POs, contracts, emails, spreadsheets, and news sentiment mentioned in SKILL.md.\n
  • Boundary markers: Not specified in the instructions.\n
  • Capability inventory: The documentation describes data consolidation and risk monitoring capabilities but provides no executable code to perform them.\n
  • Sanitization: No sanitization or validation measures for external content are mentioned.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 6, 2026, 04:43 PM
Security Audit — agent-trust-hub — vendor-management