supply-chain-decision-to-delegation

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious patterns detected. The skill instructions are designed to prevent the reckless deployment of AI by enforcing "readiness gates" and explicit human ownership of all consequential decisions.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains instructions for the agent to ingest user-supplied documents or data as evidence (SKILL.md, Phase 1). While this represents a potential attack surface, the risk is mitigated by the skill's fundamental design which requires human validation of all facts and recommendations.
  • Ingestion points: SKILL.md (Phase 1, Step 1; Interaction style instructions to extract facts from supplied documents).
  • Boundary markers: Absent; there are no specific instructions for the agent to use XML tags or other delimiters when processing user-supplied evidence.
  • Capability inventory: The skill does not utilize system-level tools or perform network/file operations, focusing strictly on analytical reporting.
  • Sanitization: Absent; the instructions do not specify sanitization or escaping of ingested text.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 07:31 AM
Security Audit — agent-trust-hub — supply-chain-decision-to-delegation