generate-tour-report

Pass

Audited by Gen Agent Trust Hub on Mar 18, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The skill generates Quarto markdown (.qmd) files containing R code for maps and charts, which are then processed using the quarto render command. This is standard functionality for Quarto-based reporting.
  • [INDIRECT_PROMPT_INJECTION]: The skill identifies a surface for indirect prompt injection as it ingests untrusted travel data (route info, waypoints, bookings) in SKILL.md. This data is interpolated into the generated document without explicit boundary markers or sanitization, though the risk is mitigated by the structured nature of the report generation.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 18, 2026, 07:14 AM