mlb-player-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface because it is designed to ingest and process data from external, untrusted web sources (e.g., FanGraphs, Baseball Savant, and RotoWire) to generate signals for downstream agents.
  • Ingestion points: Web search results for player performance statistics, weather conditions, injury reports, and lineup confirmations are retrieved and parsed by the agent (SKILL.md, resources/methodology.md).
  • Boundary markers: While the skill provides a structured YAML/Markdown template for its output, it lacks explicit instructions to the agent to treat external search content as untrusted or to use specific delimiters for raw input during processing.
  • Capability inventory: The skill performs web searches and writes structured signal files to a local directory (signals/), which are then consumed by other agents such as a lineup-optimizer or waiver-analyst (SKILL.md, resources/template.md).
  • Sanitization: The skill performs range-checking and validation on the generated numeric signals using an external mlb-signal-emitter tool, which provides a layer of output validation, though it does not explicitly sanitize the raw text content retrieved from the web.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:59 AM
Security Audit — agent-trust-hub — mlb-player-analyzer