zero-trust-expert
Pass
Audited by Gen Agent Trust Hub on Sep 11, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill's reference implementations process untrusted data sources, including authentication headers and context-aware request objects, which presents an attack surface for indirect prompt injection.
- Ingestion points: External data is ingested through Flask request objects, specifically in the
/api/loginand/api/protectedendpoints, and theAccessRequestdata structure inreferences/EXAMPLES.md. - Boundary markers: There are no explicit delimiters or instructions provided to the agent to distinguish between data and instructions within the processed objects.
- Capability inventory: The skill configuration in
SKILL.mdallows the use of theBash,Write, andEdittools, which could be misused if the agent is influenced by malicious instructions in the input data. - Sanitization: The reference code uses mock logic that lacks input sanitization or verification of the data's integrity before it is used in decision-making logic.
Audit Metadata