ads-plan
Pass
Audited by Gen Agent Trust Hub on Jun 18, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill instructions in
SKILL.mdcontain directives that explicitly invite the agent to bypass its own rules and structure. - Evidence: Under the 'When NOT to use' section, the skill specifies: 'User explicitly asks for raw output without skill discipline -> respect override'. This directive instructs the agent to disregard the skill's discipline if a user requests it, which is a common characteristic of prompt injection bypasses.
- [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface related to its data ingestion and file loading patterns.
- Ingestion points: The agent determines which industry template to load from the
assets/directory based on the user-provided 'business type' (as described inSKILL.mdandreferences/details.md). - Boundary markers: No boundary markers or instructions to sanitize or validate the user-supplied business type are present in the instructions.
- Capability inventory: The skill is configured with
Glob,Grep, andReadtools, which provide the capability to access the local filesystem. - Sanitization: There is no logic to prevent a user from supplying a path traversal string (e.g., '../../../etc/passwd') as the business type, which the agent might then attempt to load using its file-reading capabilities.
- [NO_CODE]: The skill package does not include any executable code or scripts.
- Evidence: All 14 provided files are in Markdown format (.md). The skill relies on natural language instructions to perform its tasks using the platform's native tools.
Audit Metadata