ln-11-opportunity-evaluator

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists entirely of natural language instructions for product evaluation logic. It contains no executable scripts, hardcoded credentials, or external dependencies.
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest data from external sources such as web research, community reviews, and marketplaces. This creates a surface for indirect prompt injection where malicious instructions could be embedded in the processed data. However, the skill explicitly enforces a 'read-only' contract, forbidding the creation of files, outreach, or implementation plans, which significantly mitigates the impact of potential injections.
  • [COMMAND_EXECUTION]: There are no shell commands or system-level operations defined in the skill instructions.
  • [DATA_EXFILTRATION]: The skill includes instructions to 'Keep the evaluation read-only' and forbids creating listings, advertisements, or customer outreach, effectively preventing data exfiltration during the evaluation process.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 03:18 PM
Security Audit — agent-trust-hub — ln-11-opportunity-evaluator