change-order-tracker
Pass
Audited by Gen Agent Trust Hub on May 12, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection through its automated 'Project Intelligence Integration' features. 1. Ingestion points: Data is ingested from multiple external project files including schedule.json, cost-data.json, specs-quality.json, plans-spatial.json, and directory.json. 2. Boundary markers: Absent; there are no instructions to use delimiters or to disregard potential commands embedded within the ingested data. 3. Capability inventory: The skill performs file-write operations to local project files (change-order-log.json, project-config.json) and generates .docx documents. 4. Sanitization: Absent; no validation or escaping of external data is specified before it is incorporated into the agent's operating context.
Audit Metadata