saas-erp-system-design
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to the ingestion of untrusted architectural plans and production data.\n
- Ingestion points: User-provided inputs defined in SKILL.md, including 'Current architecture, plans, policies, and constraints' and 'Production data'.\n
- Boundary markers: The instructions lack explicit delimiters or warnings to ignore instructions that might be embedded within the design inputs.\n
- Capability inventory: The skill defines workflows for mapping capabilities, objects, and controls, focusing on read-only analysis while mentioning potential configuration changes under explicit authority.\n
- Sanitization: No methods for sanitizing or validating external input data are provided.
Audit Metadata