ai-on-saas-procurement-and-questionnaire

Pass

Audited by Gen Agent Trust Hub on Jul 28, 2026

Risk Level: SAFENO_CODEPROMPT_INJECTION
Full Analysis
  • [SAFE]: No malicious behavior, obfuscation, or safety bypass attempts were detected. The skill's instructions are consistent with its stated purpose of assisting with AI procurement questionnaires.
  • [NO_CODE]: The skill consists entirely of markdown documentation and does not contain any executable scripts, source code, or binary files.
  • [PROMPT_INJECTION]: The skill is designed to process untrusted external data (buyer questionnaires), which creates a surface for indirect prompt injection. However, given the instructional nature and lack of tool-based capabilities, the risk is negligible.
  • Ingestion points: Buyer questionnaires and tender documents referenced in SKILL.md.
  • Boundary markers: None identified to isolate untrusted data from the agent's instructions.
  • Capability inventory: No scripts or tool calls were identified that could be abused via injection.
  • Sanitization: No sanitization steps are documented for the input data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 28, 2026, 06:11 AM
Security Audit — agent-trust-hub — ai-on-saas-procurement-and-questionnaire