property-listings

Pass

Audited by Gen Agent Trust Hub on Sep 9, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes property data retrieved from untrusted external sources, creating a potential surface for indirect prompt injection attacks.
  • Ingestion points: According to SKILL.md, property details are supplied by the user or verified through external tools like web_search, web_extract, or browser tools.
  • Boundary markers: The skill does not provide specific instructions or delimiters to isolate the ingested external data from the agent's internal logic, increasing the risk that embedded instructions in listing data could be followed.
  • Capability inventory: While the skill itself is a presentation recipe and does not define dangerous commands, it relies on the agent's broader toolset to gather data.
  • Sanitization: The instructions focus on deduplication and JSON formatting but do not describe methods for sanitizing or filtering untrusted content from the external sources.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 9, 2026, 10:15 AM
Security Audit — agent-trust-hub — property-listings