shop-stock-check

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data such as product names and variant metadata from shop-related tools. This data is untrusted and could contain malicious instructions designed to influence agent behavior.\n
  • Ingestion points: Data returned from shop_list_products and shop_get_product tool calls.\n
  • Boundary markers: No explicit delimiters or "ignore instructions" wrappers are defined for the interpolated tool outputs.\n
  • Capability inventory: The skill is strictly limited to discovery and retrieval tools; no mutation (update/delete) or code execution capabilities are defined.\n
  • Sanitization: No explicit sanitization or filtering of product titles or metadata is described before they are included in the final report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 02:57 PM
Security Audit — agent-trust-hub — shop-stock-check