signals-scout-logs
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted log data from external sources and uses it to drive reporting and state updates. ● Ingestion points: Log records and structured attributes retrieved via
query-logsandlogs-attributes-list. ● Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore' directives to separate log content from the agent's core instructions. ● Capability inventory: The agent possesses write access to create or edit reports (emit-report,edit-report) and can persist findings to a shared memory space (scratchpad-remember). ● Sanitization: There is no requirement for the agent to sanitize, escape, or validate log content before it is interpolated into reports or memory entries.
Audit Metadata