regtech-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides logic for ingesting and processing untrusted external data, which creates an attack surface for indirect prompt injection.\n
- Ingestion points: External data enters through the
onboard_customerandmonitor_transactionmethods inreferences/EXAMPLES.md, which handle customer identities and transaction records.\n - Boundary markers: The provided documentation and code examples do not define explicit delimiters or instructions to prevent the model from interpreting content within data fields as executable instructions.\n
- Capability inventory: The skill is configured with
BashandWebSearchtools, providing potential pathways for external interaction if an injection successfully manipulates agent behavior.\n - Sanitization: There is no evidence of sanitization, filtering, or validation logic to detect or neutralize natural language instructions embedded within the processed data.
Audit Metadata