vendor-management
Pass
Audited by Gen Agent Trust Hub on Jul 6, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists entirely of descriptive Markdown documentation. It contains no executable code, scripts, or binary assets, and does not perform any autonomous actions.\n- [PROMPT_INJECTION]: The skill describes workflows involving the ingestion of external data such as vendor emails, invoices, and news feeds. This constitutes a surface for indirect prompt injection if the skill is implemented without adequate data sanitization.\n
- Ingestion points: Vendor information from invoices, POs, contracts, emails, spreadsheets, and news sentiment mentioned in SKILL.md.\n
- Boundary markers: Not specified in the instructions.\n
- Capability inventory: The documentation describes data consolidation and risk monitoring capabilities but provides no executable code to perform them.\n
- Sanitization: No sanitization or validation measures for external content are mentioned.
Audit Metadata