partner-ecosystem

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to perform a 'public sweep' of external websites, such as competitor partner directories and review sites, to inventory ecosystem players. This ingestion of untrusted data from the open web introduces a surface for indirect prompt injection where malicious instructions embedded in those websites could attempt to influence the agent's analysis or output.
  • Ingestion points: SKILL.md (Workflow Step 2: Public sweep).
  • Boundary markers: The skill lacks explicit boundary markers or instructions for the agent to ignore or delimit potentially malicious content within the external data it gathers.
  • Capability inventory: The skill's capabilities are limited to data analysis, classification, and report generation (memo); it does not request or use high-risk tools for arbitrary command execution or external network writing.
  • Sanitization: No specific sanitization or validation protocols for external web content are provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — partner-ecosystem