scenario-analyzer

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from news headlines and real-time web search results, creating a surface for indirect prompt injection. Ingestion points: User-supplied headlines (SKILL.md, Step 1.1) and external news content retrieved via the WebSearch tool (SKILL.md, Step 2.1). Boundary markers: The skill employs Markdown headers to delimit external content within sub-agent prompts (SKILL.md, Step 2.1 and 2.2), though it does not provide explicit instructions to ignore potentially malicious commands within those inputs. Capability inventory: The agent utilizes WebSearch to fetch live data and has the capability to write report files to the local reports/ directory (SKILL.md, Step 3.2). Sanitization: The instructions do not specify any sanitization, escaping, or validation steps for the headline strings or search result content before they are used to prompt sub-agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — scenario-analyzer