data-routing
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill defines a system for the agent to ingest and process data from various untrusted external sources, which creates a surface for indirect prompt injection.
- Ingestion points: The routing table in
SKILL.mdidentifies stock news (get_stock_news), SEC filings (get_sec_filings), and research reports (get_research_reports) as primary data ingestion points. - Boundary markers: No specific delimiters or "ignore embedded instructions" warnings are defined for the agent to use when processing these external text streams.
- Capability inventory: The skill maps capabilities to tools that execute network operations and data retrieval across multiple domains and APIs.
- Sanitization: While the skill suggests a
financial_rigortool for numeric cross-validation, it provides no instructions for sanitizing or escaping natural language content from external sources before it is processed by the agent.
Audit Metadata