risk-and-issues-manager-scott-margetts

Pass

Audited by Gen Agent Trust Hub on Jun 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection through the analysis of external correspondence.
  • Ingestion Points: Processed data includes email chains, meeting notes, and call notes (SKILL.md, Step 2).
  • Boundary Markers: The instructions do not specify the use of delimiters or 'ignore' instructions to prevent the model from executing commands embedded within the emails.
  • Capability Inventory: The skill can generate .docx files, update SharePoint lists or Excel workbooks, and trigger handoffs to other agent skills such as 'budget-and-fee-manager' or 'timeline-generator'.
  • Sanitization: No sanitization, escaping, or validation of the unstructured text inputs is required by the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 26, 2026, 08:34 PM
Security Audit — agent-trust-hub — risk-and-issues-manager-scott-margetts