13-data-analysis-global

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest external data provided by the user, such as spreadsheet exports, tables, and metrics from various marketing platforms. This represents a potential surface for indirect prompt injection where malicious instructions could be embedded in the data.
  • Ingestion points: Data is ingested through user-pasted content described in the 'Information Gathering' and 'Spreadsheet Data' sections of SKILL.md.
  • Boundary markers: No explicit boundary markers or 'ignore' instructions are provided for the ingested data.
  • Capability inventory: The skill only generates a markdown report. It lacks capabilities for network operations, file system writes, or shell command execution.
  • Sanitization: No sanitization or validation of the input data is performed.
  • [SAFE]: The skill is entirely template-based and does not include any scripts, executable code, network requests, or attempts to access sensitive system files. The logic is purely analytical and focuses on generating business insights.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:39 PM
Security Audit — agent-trust-hub — 13-data-analysis-global