regtech-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill provides logic for ingesting and processing untrusted external data, which creates an attack surface for indirect prompt injection.\n
  • Ingestion points: External data enters through the onboard_customer and monitor_transaction methods in references/EXAMPLES.md, which handle customer identities and transaction records.\n
  • Boundary markers: The provided documentation and code examples do not define explicit delimiters or instructions to prevent the model from interpreting content within data fields as executable instructions.\n
  • Capability inventory: The skill is configured with Bash and WebSearch tools, providing potential pathways for external interaction if an injection successfully manipulates agent behavior.\n
  • Sanitization: There is no evidence of sanitization, filtering, or validation logic to detect or neutralize natural language instructions embedded within the processed data.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — regtech-expert