supply-chain-expert

Pass

Audited by Gen Agent Trust Hub on Sep 11, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The provided Python code implements standard supply chain modeling, including safety stock and economic order quantity calculations, with no signs of malicious behavior or obfuscation.
  • [INDIRECT_PROMPT_INJECTION]: The skill configuration creates a vulnerability surface by allowing the ingestion of external data via web searches alongside the ability to execute shell commands.
  • Ingestion points: WebSearch tool enabled in SKILL.md metadata.
  • Boundary markers: No explicit boundaries or warnings are provided to handle retrieved external content.
  • Capability inventory: Skill possesses Bash and Write access.
  • Sanitization: No sanitization logic is present for data retrieved through external tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 11, 2026, 05:13 AM
Security Audit — agent-trust-hub — supply-chain-expert