data-throughput-accelerator
Pass
Audited by Gen Agent Trust Hub on Sep 12, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and process untrusted external data sources and manifest files, which could serve as a vector for malicious instructions.
- Ingestion points: The workflow involves reading source contracts, manifest rows, and external files (SKILL.md).
- Boundary markers: The instructions do not specify the use of delimiters or boundary markers to isolate untrusted data from the prompt context.
- Capability inventory: The skill has access to tools including Bash, Read, Write, and Edit, which provide a significant capability set if an injection occurs.
- Sanitization: There is no mention of sanitizing, validating, or escaping the external content before processing or codifying the data path.
Audit Metadata