smb-router

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data to determine which powerful commands to execute.
  • Ingestion points: User-provided queries and the ## Контекст бизнеса block retrieved from session memory as described in SKILL.md.
  • Boundary markers: The instructions lack specific delimiters or instructions to ignore embedded commands within the business context block, though they do require the agent to verify the context exists.
  • Capability inventory: The skill can route to various tools with broad access across the system, including ~~бухгалтерия (accounting), ~~платежи (payments), ~~crm, and ~~почта (email).
  • Sanitization: There is no technical sanitization or validation of the input data specified; however, the skill mandates a human review checkpoint ("Always ask for confirmation before launching a command") which serves as a manual mitigation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 09:19 AM
Security Audit — agent-trust-hub — smb-router