operations-transformation

Pass

Audited by Gen Agent Trust Hub on Sep 10, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted user data in the form of business process descriptions (PROCESS_BRIEF) and conversational discovery answers. This data is sequentially processed by sub-agents (operations-process-discovery, operations-automation-validation, operations-process-redesign).
  • Ingestion points: PROCESS_BRIEF variable and user responses during SIPOC mapping stages.
  • Boundary markers: The instructions do not use specific delimiters or instructions to ignore potential commands within the user-provided process descriptions.
  • Capability inventory: The skill launches multiple sub-agents and generates structured outputs (tables and redesign blueprints) based on user input.
  • Sanitization: There is no evidence of input validation or sanitization for the provided business descriptions.
  • [EXTERNAL_DOWNLOADS]: The documentation provides an installation command fetching resources from a GitHub repository (github.com/peter-tu-zynkr/zynkr-skill-builder) and directs users to a website (zynkr.ai) for prompt-related inquiries. These external resources are consistent with the skill author's professional identity and intended use cases.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 10, 2026, 07:31 PM
Security Audit — agent-trust-hub — operations-transformation