logistics-exception-management

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONMETADATA_POISONINGNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from external, untrusted sources which could contain malicious instructions designed to influence the agent's behavior.
  • Ingestion points: The skill instructions specify that the agent will interact with and process data from "TMS (transportation management), WMS (warehouse management), carrier portals, claims management platforms, and ERP order management" (SKILL.md).
  • Boundary markers: The skill does not provide explicit delimiters or instructions to the agent to distinguish between its primary directives and the content of the logistics documents or carrier communications it processes.
  • Capability inventory: As the YAML frontmatter does not restrict tools via the allowed-tools field, the agent retains its default capabilities, which may include file system access and shell command execution to manage claims and documentation.
  • Sanitization: There is no mention of sanitization, validation, or filtering of the content retrieved from external carrier portals or shipment logs.
  • [METADATA_POISONING]: There is a minor inconsistency in the skill's metadata; the frontmatter identifies the author as "evos" and references a repository under "affaan-m," while the skill is attributed to "eugene-ee" in the distribution context. This lack of consistency can complicate the verification of the skill's origin.
  • [NO_CODE]: The skill is comprised solely of markdown documentation, templates, and decision frameworks. It does not contain any scripts, binaries, or automated installation commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 03:40 PM
Security Audit — agent-trust-hub — logistics-exception-management