cross-ref-topic-ledger
Pass
Audited by Gen Agent Trust Hub on Sep 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill defines a logical workflow for data processing and tagging within the agent's environment. It does not perform network operations, access sensitive credentials, or execute code.
- [INDIRECT_PROMPT_INJECTION]: The workflow involves ingesting external candidate summaries and a local ledger file. The instructions do not define explicit delimiters or boundary markers to isolate this external content from the agent's instructions, though the skill's read-only scope limits the potential for exploitation.
Audit Metadata