partner-ecosystem
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform a 'public sweep' of external websites, such as competitor partner directories and review sites, to inventory ecosystem players. This ingestion of untrusted data from the open web introduces a surface for indirect prompt injection where malicious instructions embedded in those websites could attempt to influence the agent's analysis or output.
- Ingestion points:
SKILL.md(Workflow Step 2: Public sweep). - Boundary markers: The skill lacks explicit boundary markers or instructions for the agent to ignore or delimit potentially malicious content within the external data it gathers.
- Capability inventory: The skill's capabilities are limited to data analysis, classification, and report generation (memo); it does not request or use high-risk tools for arbitrary command execution or external network writing.
- Sanitization: No specific sanitization or validation protocols for external web content are provided.
Audit Metadata