compliance-hardened
Warn
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: MEDIUMPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [PROMPT_INJECTION]: The skill incorporates custom behavior instructions in SKILL.md and SAFETY.md that attempt to redefine safety boundaries by training the agent to ignore social engineering framing if it classifies the task as a safe workflow. This logic could be exploited to bypass standard safety guardrails.
- [DATA_EXFILTRATION]: The agent is instructed in SKILL.md to disclose sensitive organizational data such as contract terms and pricing based on authorized status determined from the prompt context. This represents a significant exposure risk because authorization metadata in prompts can be easily spoofed.
- [DATA_EXFILTRATION]: The skill exhibits vulnerability to indirect prompt injection. Ingestion points: Processes untrusted data from DPAs and data subject requests in SKILL.md. Boundary markers: None specified. Capability inventory: Relies on default agent tools for processing and output. Sanitization: No instructions provided for escaping or validating external content.
Audit Metadata