qveris
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from a marketplace of over 60 external providers, creating a surface for indirect prompt injection if the data contains malicious instructions.
- Ingestion points: Data returned by
qveris_executeand external files retrieved viafull_content_file_url(SKILL.md, references/rest-api.md). - Boundary markers: No instructions for boundary markers or instruction-ignoring delimiters are provided for external data.
- Capability inventory: The skill uses network-enabled tools for data retrieval and allows fetching external content from signed URLs.
- Sanitization: There is no mention of sanitizing or validating the integrity of the payloads before they are processed by the agent.
- [EXTERNAL_DOWNLOADS]: The skill defines a process for fetching large data payloads from dynamically generated signed URLs.
- Evidence: The skill instructions state "If the full JSON is required, fetch that signed URL and use the full payload" in SKILL.md.
Audit Metadata