counterparty-risk
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the agent to process various external and untrusted data sources, including counterparty legal entity maps, external credit ratings, financial scoring metrics, and CDS market data, which presents a surface for indirect prompt injection.
- Ingestion points: Identification of legal entities, credit quality assessments, and use of external valuation sources documented in SKILL.md and references/examples.md.
- Boundary markers: The instructions do not define the use of delimiters or boundary markers to isolate untrusted external content from the agent's core instructions.
- Capability inventory: The workflows involve sensitive financial operations such as exposure measurement, collateral management, and default close-out actions, which imply integration with risk and trading systems.
- Sanitization: The instructions lack specifications for sanitizing or validating external data inputs before they are processed by the agent.
Audit Metadata