risk-management
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection vulnerability surface. The skill ingests data from multiple external sources to automate risk identification.
- Ingestion points: schedule.json, directory.json, quality-data.json, labor-tracking.json, cost-data.json, delay-log.json, procurement-log.json, and submittal-log.json.
- Boundary markers: Absent. The instructions lack specific delimiters or directions to ignore instructions potentially embedded in these external files.
- Capability inventory: The skill performs file read and write operations locally (e.g., risk-register.json) and generates reports (.docx). No shell execution or network capabilities were identified.
- Sanitization: Absent. The skill does not describe any validation or filtering logic for the data it processes from project files.
Audit Metadata