cloud-cost-optimization

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection vulnerability surface through the processing of untrusted external data.\n
  • Ingestion points: The agent protocol in SKILL.md identifies "Billing data" as required input context for generating reports.\n
  • Boundary markers: Absent. No delimiters or instructions are provided to the agent to differentiate between its system instructions and the content of the potentially attacker-controlled billing data.\n
  • Capability inventory: The skill relies on default agent capabilities for file processing and reporting without restrictive scoping.\n
  • Sanitization: Absent. There are no defined procedures for filtering or validating the ingested information.\n- [PROMPT_INJECTION]: The skill contains multiple large reference files (e.g., references/performance-optimization.md and references/deployment-pipelines.md) that include 150 sections each of nearly identical technical content. This volume of repetitive filler text may be intended to manipulate model behavior via context stuffing or by biasing the agent's reasoning process.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 02:16 PM
Security Audit — agent-trust-hub — cloud-cost-optimization