competitive-poc-rfp-plan

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill consists exclusively of Markdown instructions and templates. No executable code, scripts, or binaries are included.
  • [SAFE]: Context acquisition is handled through platform-defined tool capabilities for internal data sources and the vendor's own tracking system. No network requests to unknown third-party domains were detected.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data such as buyer requirements and RFPs. Ingestion points include referenced files and user-provided documents. Boundary markers involve labeling requirements by source in SKILL.md and identifying competitor-specific vocabulary in methodology references. Capability inventory shows only information retrieval and text generation tasks with no dangerous execution tools. Sanitization relies on manual verification against approved documentation as described in the workflow.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 06:04 PM
Security Audit — agent-trust-hub — competitive-poc-rfp-plan