signals-scout-logs

Pass

Audited by Gen Agent Trust Hub on Jul 21, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is vulnerable to indirect prompt injection as it ingests untrusted log data from external sources and uses it to drive reporting and state updates. ● Ingestion points: Log records and structured attributes retrieved via query-logs and logs-attributes-list. ● Boundary markers: Absent; the instructions do not specify the use of delimiters or 'ignore' directives to separate log content from the agent's core instructions. ● Capability inventory: The agent possesses write access to create or edit reports (emit-report, edit-report) and can persist findings to a shared memory space (scratchpad-remember). ● Sanitization: There is no requirement for the agent to sanitize, escape, or validate log content before it is interpolated into reports or memory entries.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 21, 2026, 08:12 PM
Security Audit — agent-trust-hub — signals-scout-logs