counterparty-risk

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to process various external and untrusted data sources, including counterparty legal entity maps, external credit ratings, financial scoring metrics, and CDS market data, which presents a surface for indirect prompt injection.
  • Ingestion points: Identification of legal entities, credit quality assessments, and use of external valuation sources documented in SKILL.md and references/examples.md.
  • Boundary markers: The instructions do not define the use of delimiters or boundary markers to isolate untrusted external content from the agent's core instructions.
  • Capability inventory: The workflows involve sensitive financial operations such as exposure measurement, collateral management, and default close-out actions, which imply integration with risk and trading systems.
  • Sanitization: The instructions lack specifications for sanitizing or validating external data inputs before they are processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:25 AM
Security Audit — agent-trust-hub — counterparty-risk