company-filing-research
Pass
Audited by Gen Agent Trust Hub on Aug 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection via the filings and disclosures it is designed to ingest.
- Ingestion points: SKILL.md specifies a workflow to collect and read external company filings such as 10-K, 10-Q, and 8-K reports.
- Boundary markers: No delimiters or instructions are provided to the agent to help it distinguish between the skill's primary instructions and potentially adversarial content within the ingested filings.
- Capability inventory: The skill has the capability to write summarized evidence to the local filesystem at research/targets/evidence/filings/ as defined in the SKILL.md workflow.
- Sanitization: The skill lacks instructions to sanitize or validate the content of external filings before they are incorporated into the agent's context.
Audit Metadata