fictiv
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external sources, specifically the Fictiv web application, creating a potential surface for indirect prompt injection via content like DFM feedback cards, account manager profiles, or shared workspace messages. Ingestion points: Browser DOM text, external feedback summaries, and communication logs from app.fictiv.com. Boundary markers: The skill contains explicit instructions in SKILL.md (Ground Rule 6) for the agent to treat page content as data and ignore any instructions found within it. Capability inventory: The skill can execute local scripts, perform browser-based JavaScript automation, and initiate manufacturing orders (protected by a user approval gate). Sanitization: The skill relies on clear instructional constraints for the agent to mitigate the risk of obeying embedded commands.
Audit Metadata