commerce-morning-brief

Pass

Audited by Gen Agent Trust Hub on Aug 19, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The instructions include a directive to skip a specific review chaining process, which constitutes a constraint removal or bypass attempt.
  • Evidence: "ai-slop-reviewer 체이닝은 제외합니다" (Excludes ai-slop-reviewer chaining) found in the skill description.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external files and screenshots, which is then written to the local filesystem.
  • Ingestion points: User-provided CSV/Excel dashboard exports, screenshots, and pasted text as described in the "매장 데이터" input slot.
  • Boundary markers: The skill does not define specific delimiters or instructions to ignore embedded commands within the ingested data.
  • Capability inventory: The skill can read data via MCP connectors or files and has the capability to write markdown files (".md") to the local filesystem.
  • Sanitization: There is no mention of sanitizing or validating the content of the external files before processing and summarizing them.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 19, 2026, 01:42 PM
Security Audit — agent-trust-hub — commerce-morning-brief