python-background-jobs

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes patterns for ingesting external data (such as API requests and webhooks) into background tasks, which creates a potential surface for indirect prompt injection if the processed content is later used in an LLM context without sanitization.
  • Ingestion points: The start_export function and process_webhook task in SKILL.md receive external parameters and payloads.
  • Boundary markers: The provided code examples do not include explicit instructions or delimiters to ignore embedded commands within the processed data.
  • Capability inventory: The skill demonstrates capabilities for database operations, network requests (sending emails and webhooks), and task orchestration.
  • Sanitization: No explicit sanitization or validation logic for the content of the external payload or request is present in the snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 11:20 PM
Security Audit — agent-trust-hub — python-background-jobs