mlb-trade-evaluator

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data which could serve as a vector for indirect prompt injection attacks.
  • Ingestion points: Processes trade proposals pasted from Yahoo by the user and fetches rest-of-season projections from various external baseball websites (Step 1 and Step 2 in SKILL.md).
  • Boundary markers: The instructions do not mandate the use of delimiters or system prompts to ignore potential instructions embedded in the external data.
  • Capability inventory: The skill writes decision logs to tracker/decisions-log.md and evaluation signals to signals/YYYY-MM-DD-trade-<opponent>.md. It also invokes the @skills/adverse-selection-prior/ skill.
  • Sanitization: No specific data sanitization or validation logic is defined for the external inputs.- [EXTERNAL_DOWNLOADS]: The skill retrieves data from well-known and reputable baseball analytics services.
  • Evidence: Accesses FanGraphs (ATC and Auction Calculator), Razzball, FantasyPros, and RotoWire for rest-of-season projections and player valuation.- [COMMAND_EXECUTION]: The skill instructs the agent to perform web searches and data retrieval tasks.
  • Evidence: Workflow Step 2 directs the agent to 'Pull rest-of-season ATC projections for every player... from web search.'
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 05:59 AM
Security Audit — agent-trust-hub — mlb-trade-evaluator