skills/openai/plugins/kpi-reporting/Gen Agent Trust Hub

kpi-reporting

Pass

Audited by Gen Agent Trust Hub on Sep 6, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to synthesize reports by analyzing information from sources like company documents and team communications. This activity presents a surface where instructions embedded in processed data could potentially influence the agent's behavior during report generation.
  • Ingestion points: Data is retrieved from ~~company_docs, ~~team_communication, and ~~structured_data as outlined in SKILL.md.
  • Boundary markers: The instructions do not specify the use of clear delimiters or warnings to separate data content from operational instructions.
  • Capability inventory: The skill has the capability to query external sources and produce artifacts via tools like $build-report and $report-to-google-slides.
  • Sanitization: There are no explicit requirements for sanitizing external data before incorporating it into the final KPI readouts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 6, 2026, 11:17 AM
Security Audit — agent-trust-hub — kpi-reporting