automation-sandbox-post-copy-config-generate

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function is to ingest and process untrusted data from multiple file formats (PDF, XLSX, CSV, JSON, DOCX, and images). This creates a significant surface for indirect prompt injection attacks, where instructions hidden within the SOP files could hijack the agent's behavior.
  • Ingestion points: Processes external files including PDF, XLSX, DOCX, CSV, JSON, and various image formats (.png, .jpg, etc.).
  • Boundary markers: Absent. The instructions do not explicitly command the agent to ignore or delimit instructions found within the processed SOP data.
  • Capability inventory: The skill utilizes file reading, OCR (via tesseract), and file writing (post-copy-config.json).
  • Sanitization: Absent. Instructions explicitly state that values (including URLs that may contain secrets) should be embedded verbatim.
  • [DYNAMIC_EXECUTION]: The file references/source_format_handling.md contains functional Python code snippets for handling various document formats. The agent is instructed to use these recipes, which involves the dynamic application of code logic to process untrusted input at runtime.
  • [DATA_EXFILTRATION]: The skill is designed to extract and store sensitive information, specifically noting that SOPs may include secrets in URLs (e.g., https://USER:TOKEN@host/...). While the skill instructs the agent to flag these to the user, the routine extraction and storage of hardcoded credentials in the generated JSON output constitutes a data handling risk.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 04:28 PM
Security Audit — agent-trust-hub — automation-sandbox-post-copy-config-generate