business-analyst
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze potentially untrusted external information (e.g., market research, customer feedback, and competitive intelligence) using data-processing capabilities, which introduces a vulnerability to indirect injection attacks.
- Ingestion points: The agent is instructed to ingest and analyze customer churn patterns, sales funnel data, and market research information (SKILL.md).
- Boundary markers: The instructions do not define clear delimiters or "ignore instructions" tags to isolate untrusted data from the agent's core operational logic.
- Capability inventory: The skill highlights capabilities for executing custom analytics with Python, R, and SQL, and interfacing with platforms like Snowflake and BigQuery (SKILL.md).
- Sanitization: There are no explicit instructions for the agent to sanitize, validate, or escape external content before processing it or interpolating it into prompts.
Audit Metadata