supply-chain-decision-to-delegation
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious patterns detected. The skill instructions are designed to prevent the reckless deployment of AI by enforcing "readiness gates" and explicit human ownership of all consequential decisions.
- [INDIRECT_PROMPT_INJECTION]: The skill contains instructions for the agent to ingest user-supplied documents or data as evidence (SKILL.md, Phase 1). While this represents a potential attack surface, the risk is mitigated by the skill's fundamental design which requires human validation of all facts and recommendations.
- Ingestion points:
SKILL.md(Phase 1, Step 1; Interaction style instructions to extract facts from supplied documents). - Boundary markers: Absent; there are no specific instructions for the agent to use XML tags or other delimiters when processing user-supplied evidence.
- Capability inventory: The skill does not utilize system-level tools or perform network/file operations, focusing strictly on analytical reporting.
- Sanitization: Absent; the instructions do not specify sanitization or escaping of ingested text.
Audit Metadata