client-proposal-generator

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill is designed for professional document generation and follows a structured workflow without any malicious instructions or hidden behaviors. It correctly manages client information and adheres to its stated purpose.
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses a data ingestion surface through web research, which is a common vulnerability for indirect prompt injection where instructions could be hidden on external websites.
  • Ingestion points: Client research results from WebSearch and Bash (references/research.md).
  • Boundary markers: Not explicitly defined in the instructions for isolating external content.
  • Capability inventory: The skill has access to Bash for system commands and Write for file creation (SKILL.md).
  • Sanitization: There is no explicit sanitization or filtering logic applied to the external content before it is used for personalization in the final document.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 07:25 AM
Security Audit — agent-trust-hub — client-proposal-generator