risk-management

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection vulnerability surface. The skill ingests data from multiple external sources to automate risk identification.
  • Ingestion points: schedule.json, directory.json, quality-data.json, labor-tracking.json, cost-data.json, delay-log.json, procurement-log.json, and submittal-log.json.
  • Boundary markers: Absent. The instructions lack specific delimiters or directions to ignore instructions potentially embedded in these external files.
  • Capability inventory: The skill performs file read and write operations locally (e.g., risk-register.json) and generates reports (.docx). No shell execution or network capabilities were identified.
  • Sanitization: Absent. The skill does not describe any validation or filtering logic for the data it processes from project files.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 09:54 PM
Security Audit — agent-trust-hub — risk-management