guidewire-migration-and-upgrade

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to process outputs from database queries and API responses, which could potentially contain malicious instructions if the source environment or data (e.g., policy numbers, claim notes) is compromised.
  • Ingestion points: SKILL.md (Example 3) uses psql and curl to fetch policy data. references/API_REFERENCE.md describes processing HTTP headers (Sunset, Deprecation) and integration logs.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the data being processed.
  • Capability inventory: The skill is granted access to Bash, Write, and Edit tools, which could be leveraged if an injection is successful.
  • Sanitization: No explicit sanitization or validation logic is provided for the data fetched from external tool outputs.
  • [EXTERNAL_DOWNLOADS]: The skill references official documentation and technical guidance from well-known industry sources.
  • Evidence: The skill provides links to official Guidewire documentation at docs.guidewire.com and technical blog posts at martinfowler.com to support the migration workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 03:46 AM
Security Audit — agent-trust-hub — guidewire-migration-and-upgrade