skills/jeremylongshore/tons-of-skills-marketplace/guidewire-migration-and-upgrade/Gen Agent Trust Hub
guidewire-migration-and-upgrade
Pass
Audited by Gen Agent Trust Hub on Sep 9, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process outputs from database queries and API responses, which could potentially contain malicious instructions if the source environment or data (e.g., policy numbers, claim notes) is compromised.
- Ingestion points:
SKILL.md(Example 3) usespsqlandcurlto fetch policy data.references/API_REFERENCE.mddescribes processing HTTP headers (Sunset,Deprecation) and integration logs. - Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the data being processed.
- Capability inventory: The skill is granted access to
Bash,Write, andEdittools, which could be leveraged if an injection is successful. - Sanitization: No explicit sanitization or validation logic is provided for the data fetched from external tool outputs.
- [EXTERNAL_DOWNLOADS]: The skill references official documentation and technical guidance from well-known industry sources.
- Evidence: The skill provides links to official Guidewire documentation at
docs.guidewire.comand technical blog posts atmartinfowler.comto support the migration workflow.
Audit Metadata