temporal
Pass
Audited by Gen Agent Trust Hub on Jun 15, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill provides templates for agents that ingest untrusted data from user signals and external activities, creating a potential surface for indirect prompt injection.
- Ingestion points: Untrusted data enters the agent context through signals in 'on_task_event_send' and via activities that perform web scraping (e.g., 'scrape_url' in 'activities.py').
- Boundary markers: The provided examples lack clear delimiters or specific instructions to the agent to treat external content as data rather than instructions.
- Capability inventory: The agents documented have access to network I/O (via 'httpx'), LLM interaction (via 'adk.providers.litellm'), and persistent state modification (via MongoDB).
- Sanitization: The guide does not demonstrate input validation, filtering, or sanitization of content retrieved from external URLs before it is processed by the LLM.
Audit Metadata