gestao-clientes
Pass
Audited by Gen Agent Trust Hub on Apr 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through the
bulk_import_clientsfunction, which is designed to process data from external URLs provided via thecsv_file_urlparameter. - Ingestion points: The
csv_file_urlparameter inresources/client-management.yamlallows the agent to fetch and ingest untrusted external content. - Boundary markers: The skill definition does not provide boundary markers or instructions to the agent to disregard instructions found within the imported data.
- Capability inventory: The skill allows for the creation, modification, and export of sensitive client records and financial statistics, which could be abused if an injection attack succeeds.
- Sanitization: There is no evidence of validation or sanitization of the CSV file content before it is processed by the agent.
Audit Metadata