mlb-faab-sizer
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests data from external tracking files and user-supplied signals to generate bid rationales, which creates a potential surface for indirect prompt injection if source data included malicious instructions.
- Ingestion points: Accesses
yahoo-mlb/tracker/faab-log.mdandcontext/team-profile.mdfor historical bid data and opponent profiles. - Boundary markers: Structural headers are used in templates, but the skill lacks explicit delimiters or instruction-isolation markers for processed data values.
- Capability inventory: Invokes sibling skills for calculations and uses tools like
mlb-signal-emitterto output recommendations. - Sanitization: No validation or filtering of text content from ingested data is specified before its inclusion in the final user-facing rationale.
Audit Metadata