smb-router
Pass
Audited by Gen Agent Trust Hub on Sep 7, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data to determine which powerful commands to execute.
- Ingestion points: User-provided queries and the
## Контекст бизнесаblock retrieved from session memory as described inSKILL.md. - Boundary markers: The instructions lack specific delimiters or instructions to ignore embedded commands within the business context block, though they do require the agent to verify the context exists.
- Capability inventory: The skill can route to various tools with broad access across the system, including
~~бухгалтерия(accounting),~~платежи(payments),~~crm, and~~почта(email). - Sanitization: There is no technical sanitization or validation of the input data specified; however, the skill mandates a human review checkpoint ("Always ask for confirmation before launching a command") which serves as a manual mitigation.
Audit Metadata