run-campaign

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external business systems and user-provided files which may contain untrusted instructions.\n- Ingestion points: Financial and sales records retrieved via platform connectors for accounting (~~бухгалтерия, ~~платежи) and customer relationship management (~~crm), as well as manual CSV file uploads.\n- Boundary markers: Absent. The skill instructions do not specify the use of delimiters or instructions to ignore embedded commands in the ingested data.\n- Capability inventory: The skill is configured to use Read, WebFetch, and Bash capabilities for processing data and interacting with external services.\n- Sanitization: Absent. There is no evidence of validation or filtering for the content retrieved from external systems or uploaded files.\n- [DATA_EXFILTRATION]: The skill is designed to access and process sensitive financial and business data from accounting systems (1C, MojSklad), payment processors (YUKassa), and CRM platforms (Bitrix24, amoCRM). While no specific malicious network destinations are hardcoded, the combination of sensitive data access and the availability of network-enabled tools creates a potential risk surface.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 04:26 PM
Security Audit — agent-trust-hub — run-campaign