ai-agent-commercial-packaging
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is composed entirely of markdown instructions and does not contain any executable scripts, shell commands, or remote code download patterns.
- [SAFE]: No obfuscation, hidden URLs, or malicious character encodings were detected.
- [PROMPT_INJECTION]: The skill describes an indirect prompt injection surface as it requires the agent to ingest external documents such as 'commercial briefs' and 'contract records'.
- Ingestion points: SKILL.md (Workflow steps 1 and 2).
- Boundary markers: None explicitly defined for untrusted input ingestion.
- Capability inventory: Read access to commercial records and drafting authority for proposal artifacts; no network or shell execution capabilities are requested.
- Sanitization: The workflow includes verification steps to cross-check outputs against evidence and requires finance/legal review markers.
- Note: This is an inherent risk of data processing and is addressed by the skill's procedural guardrails.
Audit Metadata