automation
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data through webhooks and retrieval-augmented generation (RAG) pipelines. 1. Ingestion points: External API responses and webhook payloads (references/integrations.md) and knowledge base corpora (references/rag.md). 2. Boundary markers: The skill includes explicit instructions to isolate system instructions from untrusted user data and maintain prompt-injection boundaries (references/prompt.md). 3. Capability inventory: The skill has access to shell execution (bash, run_command) and file system modifications (write_to_file, replace_file_content). 4. Sanitization: Procedures include HMAC signature verification for webhooks and mandatory validation/sanitization of inbound payloads (references/integrations.md).
- [SAFE]: The skill implements strong credential security practices, directing the use of external secret stores like Bitwarden and emphasizing that secrets must never be stored in code or logs.
- [SAFE]: Browser automation (Browser Relay) includes specific privacy guardrails, such as binding to the local loopback interface and redacting sensitive financial or personal information before logging.
Audit Metadata