enterprise-search-source

Pass

Audited by Gen Agent Trust Hub on Apr 18, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [NO_CODE]: The skill consists exclusively of markdown documentation and contains no executable scripts, automation code, or shell commands.
  • [SAFE]: No security issues were detected. The contents are limited to guiding the agent on how to prioritize and manage search queries across connected enterprise tools.
  • [PROMPT_INJECTION]: The skill documents a surface for Indirect Prompt Injection as it is designed to process data from various external enterprise sources.
  • Ingestion points: External data enters the agent context via MCP tools for chat, email, cloud storage, CRM, and project tracking as described in SKILL.md.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded prompts within the retrieved search results.
  • Capability inventory: The agent is authorized to search and read contents from multiple external platforms.
  • Sanitization: No sanitization or validation of the external search content is mentioned in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 18, 2026, 12:08 PM
Security Audit — agent-trust-hub — enterprise-search-source