adverse-selection-prior
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill represents a surface for indirect prompt injection as it ingests untrusted data from external offers (e.g., offer type, proposer archetype, symmetry scores) to perform its calculations. However, the risk is negligible due to the lack of exploitable capabilities.
- Ingestion points: The skill ingests inputs including
offer_type,proposer_archetype,offer_symmetry_score, andproposer_info_asymmetryas described inSKILL.md. - Boundary markers: Absent. The instructions do not define specific delimiters or instructions to ignore embedded commands within the input data.
- Capability inventory: The skill does not request or use any tools, network access, or file-writing capabilities.
- Sanitization: Absent. The skill relies on the agent to interpret inputs as specific enums or integers without explicit validation or escaping logic.
- [SAFE]: All mathematical formulas and logic templates, including the Python-style pseudocode in
resources/template.md, are provided as instructional guidance for the agent and do not involve dynamic code execution or unsafe operations.
Audit Metadata