service-itsm-agentic-setup-cmdb-coordinate
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to extract context and progress status (which setup layers are complete) by scanning the chat history and conversation transcript.
- Ingestion points: Chat history and conversation transcript (SKILL.md, Behavior step 1).
- Boundary markers: Absent. The skill derives status from the most recent layer activity in the transcript without specific delimiters for untrusted data.
- Capability inventory: This skill serves as an orchestrator for child skills that perform high-privilege operations, including tenant provisioning, feature enablement, and permission-set assignments in production or sandbox environments.
- Sanitization: The skill instructions include a mitigation strategy requiring the agent to re-confirm the status with the user if the derivation is ambiguous or the conversation has been resumed after a delay.
Audit Metadata