grant-access
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user input (usernames, emails, and service names) to perform privileged actions including sending tailnet invites and modifying Access Control Lists (ACLs). This vulnerability surface allows for potential manipulation of security policies if the agent blindly trusts the input provided during conversation. The skill includes manual verification steps (e.g., "Verify from both sides", "Read the live policy before proposing any change") which serve as mitigations to ensure configuration integrity.
Audit Metadata