cowork-rfp-response
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingest data from external RFP documents and internal company material folders, making it susceptible to indirect prompt injection attacks.
- Ingestion points: The skill processes RFP documents and various company materials (past proposals, case studies, bios, certifications) as specified in the workflow.
- Boundary markers: No explicit delimiters or instructions are provided to the agent to treat the document content as raw data or to ignore instructions embedded within the files.
- Capability inventory: The skill utilizes powerful tools including Read, Glob, Grep, Write, Bash, and WebSearch, which could be misused if an injection is successful.
- Sanitization: There is no evidence of sanitization or validation of the text extracted from the source documents before it is processed by the agent.
Audit Metadata