saas-replacement-planner
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill requests and uses the Bash tool to facilitate its analysis and generate the output replacement plan, providing the agent with broad shell access.
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external sources and user-provided financial files to perform its analysis. 1. Ingestion points: Workflow Step 1 (bank statements, CSV files, and screenshots) and Workflow Step 2 (WebSearch results for pricing verification). 2. Boundary markers: Absent; the instructions do not implement delimiters or 'ignore' instructions for the external content processed by the model. 3. Capability inventory: Bash, Write, Edit, Glob, and Grep tools are requested in the SKILL.md frontmatter. 4. Sanitization: Absent; no validation, escaping, or sanitization logic for content from external files or web searches is described in the provided references.
Audit Metadata