mlb-regression-flagger

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external websites (Baseball Savant and FanGraphs) to perform regression index calculations. Processing external web content presents a potential surface for indirect prompt injection where malicious instructions could theoretically be embedded in the retrieved data.
  • Ingestion points: Player statistics and Statcast data are retrieved from baseballsavant.mlb.com and fangraphs.com.
  • Boundary markers: None explicitly defined for the external web content.
  • Capability inventory: The skill computes mathematical formulas and writes results to signal files in the local filesystem.
  • Sanitization: No specific text sanitization is mentioned, though the workflow focuses on extracting numerical values.
  • [EXTERNAL_DOWNLOADS]: The skill instructions direct the agent to fetch data from well-known and reputable sports domains, including baseballsavant.mlb.com and fangraphs.com. These references are documented and essential for the skill's primary function of baseball analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:59 AM
Security Audit — agent-trust-hub — mlb-regression-flagger