supply-chain-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The provided Python code implements standard supply chain modeling, including safety stock and economic order quantity calculations, with no signs of malicious behavior or obfuscation.
- [INDIRECT_PROMPT_INJECTION]: The skill configuration creates a vulnerability surface by allowing the ingestion of external data via web searches alongside the ability to execute shell commands.
- Ingestion points: WebSearch tool enabled in SKILL.md metadata.
- Boundary markers: No explicit boundaries or warnings are provided to handle retrieved external content.
- Capability inventory: Skill possesses Bash and Write access.
- Sanitization: No sanitization logic is present for data retrieved through external tools.
Audit Metadata