pricing-strategy
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by instructing the agent to ingest and analyze untrusted data from multiple sources including user-provided arguments, external files (such as survey data and financial models), and live web search results.
- Ingestion points: Data enters the context via the
$ARGUMENTSvariable, file-read operations on user-supplied documents, and output from web search tools as specified in the Instructions and Context sections ofSKILL.md. - Boundary markers: Absent. The instructions do not include delimiters or specific guidance for the agent to distinguish between analysis instructions and potentially malicious commands embedded within the analyzed data.
- Capability inventory: The agent uses file reading and web search capabilities to perform its task.
- Sanitization: Absent. There are no instructions or mechanisms defined to sanitize, filter, or validate the content retrieved from external sources before processing it.
Audit Metadata