fictiv

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically the Fictiv web application, creating a potential surface for indirect prompt injection via content like DFM feedback cards, account manager profiles, or shared workspace messages. Ingestion points: Browser DOM text, external feedback summaries, and communication logs from app.fictiv.com. Boundary markers: The skill contains explicit instructions in SKILL.md (Ground Rule 6) for the agent to treat page content as data and ignore any instructions found within it. Capability inventory: The skill can execute local scripts, perform browser-based JavaScript automation, and initiate manufacturing orders (protected by a user approval gate). Sanitization: The skill relies on clear instructional constraints for the agent to mitigate the risk of obeying embedded commands.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 07:50 AM
Security Audit — agent-trust-hub — fictiv