evidence-case-viewer

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The application constructs LLM prompts by concatenating the pipeline state, which includes the raw user question, with chat messages in bridge.py. This lacks sanitization or explicit boundary markers, allowing potentially malicious instructions in the question to influence the subagent's behavior. Ingestion points include command-line arguments in app.py and the GUI chat well in bridge.py. Capabilities include network communication with an external agent service. There is no evidence of escaping or filtering applied to the question or chat message before prompt construction.
  • [DATA_EXFILTRATION]: Through the --subagent-url argument in app.py, the skill can be configured to send pipeline data to any URL. The bridge.py script transmits the question, entity markup, gate statuses, and evidence QRAs to this URL via POST requests to the /chat/stream endpoint, presenting a risk of data exposure if an untrusted endpoint is provided by the user.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 06:01 PM
Security Audit — agent-trust-hub — evidence-case-viewer