evidence-case-viewer
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The application constructs LLM prompts by concatenating the pipeline state, which includes the raw user question, with chat messages in
bridge.py. This lacks sanitization or explicit boundary markers, allowing potentially malicious instructions in the question to influence the subagent's behavior. Ingestion points include command-line arguments inapp.pyand the GUI chat well inbridge.py. Capabilities include network communication with an external agent service. There is no evidence of escaping or filtering applied to the question or chat message before prompt construction. - [DATA_EXFILTRATION]: Through the
--subagent-urlargument inapp.py, the skill can be configured to send pipeline data to any URL. Thebridge.pyscript transmits the question, entity markup, gate statuses, and evidence QRAs to this URL via POST requests to the/chat/streamendpoint, presenting a risk of data exposure if an untrusted endpoint is provided by the user.
Audit Metadata