scenario-analyzer
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from news headlines and real-time web search results, creating a surface for indirect prompt injection. Ingestion points: User-supplied headlines (SKILL.md, Step 1.1) and external news content retrieved via the WebSearch tool (SKILL.md, Step 2.1). Boundary markers: The skill employs Markdown headers to delimit external content within sub-agent prompts (SKILL.md, Step 2.1 and 2.2), though it does not provide explicit instructions to ignore potentially malicious commands within those inputs. Capability inventory: The agent utilizes WebSearch to fetch live data and has the capability to write report files to the local reports/ directory (SKILL.md, Step 3.2). Sanitization: The instructions do not specify any sanitization, escaping, or validation steps for the headline strings or search result content before they are used to prompt sub-agents.
Audit Metadata