business-analyst

Pass

Audited by Gen Agent Trust Hub on Sep 4, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process and analyze potentially untrusted external information (e.g., market research, customer feedback, and competitive intelligence) using data-processing capabilities, which introduces a vulnerability to indirect injection attacks.
  • Ingestion points: The agent is instructed to ingest and analyze customer churn patterns, sales funnel data, and market research information (SKILL.md).
  • Boundary markers: The instructions do not define clear delimiters or "ignore instructions" tags to isolate untrusted data from the agent's core operational logic.
  • Capability inventory: The skill highlights capabilities for executing custom analytics with Python, R, and SQL, and interfacing with platforms like Snowflake and BigQuery (SKILL.md).
  • Sanitization: There are no explicit instructions for the agent to sanitize, validate, or escape external content before processing it or interpolating it into prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 4, 2026, 03:04 PM
Security Audit — agent-trust-hub — business-analyst