next
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Potential for indirect prompt injection through audit data ingestion. * Ingestion points: Processes external data from findings.json and parameters passed through $ARGUMENTS in SKILL.md. * Boundary markers: No explicit delimiters are defined to separate instructions from the data in findings.json. * Capability inventory: The skill is configured with Bash and Read tools, creating a risk surface if untrusted data influences the agent's use of these tools. * Sanitization: No sanitization or structure validation is present for the files being read.
Audit Metadata