planning
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes potentially untrusted data from external sources (via the research tool) and user-provided files (via parse-file). This content is used to build a dependency-aware task graph for the create-tasks tool, which can trigger automated actions.
- Ingestion points: Data from research and parse-file tools.
- Boundary markers: The skill uses structured executor briefings for tasks (e.g., Outcome, Trigger mode, External systems) but lacks explicit instructions to disregard instructions embedded within ingested data.
- Capability inventory: Includes the create-tasks tool for triggering execution, as well as workflows and credentials for environment management.
- Sanitization: No explicit sanitization or validation of external content is defined.
Audit Metadata