ai-on-saas-procurement-and-questionnaire
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
- [SAFE]: No malicious behavior, obfuscation, or safety bypass attempts were detected. The skill's instructions are consistent with its stated purpose of assisting with AI procurement questionnaires.
- [NO_CODE]: The skill consists entirely of markdown documentation and does not contain any executable scripts, source code, or binary files.
- [PROMPT_INJECTION]: The skill is designed to process untrusted external data (buyer questionnaires), which creates a surface for indirect prompt injection. However, given the instructional nature and lack of tool-based capabilities, the risk is negligible.
- Ingestion points: Buyer questionnaires and tender documents referenced in SKILL.md.
- Boundary markers: None identified to isolate untrusted data from the agent's instructions.
- Capability inventory: No scripts or tool calls were identified that could be abused via injection.
- Sanitization: No sanitization steps are documented for the input data.
Audit Metadata