sourcing-summarization
Pass
Audited by Gen Agent Trust Hub on May 20, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill identifies an indirect prompt injection attack surface related to data ingestion from ServiceNow records.
- Ingestion points: The skill retrieves data from ServiceNow tables including
proc_sourcing_event,proc_negotiation,core_company,ast_contract, andproc_poinSKILL.md. - Boundary markers: Absent. The instructions lack specific delimiters or directions for the agent to ignore instructions embedded in fetched data.
- Capability inventory: The skill leverages ServiceNow MCP tools (
SN-Query-Table,SN-Read-Record) and REST APIs, and it includes access toBashas a native tool. - Sanitization: Absent. No evidence of content sanitization or validation was found for data retrieved from external fields before agent processing.
Audit Metadata