sourcing-summarization

Pass

Audited by Gen Agent Trust Hub on May 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies an indirect prompt injection attack surface related to data ingestion from ServiceNow records.
  • Ingestion points: The skill retrieves data from ServiceNow tables including proc_sourcing_event, proc_negotiation, core_company, ast_contract, and proc_po in SKILL.md.
  • Boundary markers: Absent. The instructions lack specific delimiters or directions for the agent to ignore instructions embedded in fetched data.
  • Capability inventory: The skill leverages ServiceNow MCP tools (SN-Query-Table, SN-Read-Record) and REST APIs, and it includes access to Bash as a native tool.
  • Sanitization: Absent. No evidence of content sanitization or validation was found for data retrieved from external fields before agent processing.
Audit Metadata
Risk Level
SAFE
Analyzed
May 20, 2026, 01:35 PM
Security Audit — agent-trust-hub — sourcing-summarization