saas-poc-and-pilot-scoping
Pass
Audited by Gen Agent Trust Hub on Jul 28, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The analyzed file is a pure markdown instruction set without any embedded scripts, command execution, or network operations.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external data such as tender documents, discovery records, and architecture evidence. While this creates a theoretical surface for indirect prompt injection (Category 8), the risk is minimal as the skill's capabilities are restricted to drafting proposal artifacts within a workspace, and it explicitly includes a 'Stop condition' that pauses operations if inputs are missing or contradictory.
- Ingestion points: Tender documents, discovery records, architecture diagrams, and commercial evidence supplied in the workspace (referenced in 'Capability and Permission Boundaries').
- Boundary markers: None explicitly defined for the data ingestion process.
- Capability inventory: Reads workspace files; drafts proposal sections. No subprocess, network, or filesystem write operations beyond document generation are present.
- Sanitization: No explicit sanitization or filtering of external input is mentioned.
- [DATA_EXPOSURE]: The skill mentions handling sensitive business data (pricing, security evidence). However, it includes explicit instructions for the agent to maintain confidentiality and avoid unauthorized disclosure or contractual commitments.
Audit Metadata