qlik-load-script

Pass

Audited by Gen Agent Trust Hub on Aug 7, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and process user-provided or existing .qvs script files from the file system. This creates an attack surface for indirect prompt injection, as the agent may inadvertently follow instructions embedded within the script comments or data of these files. There are no explicit boundary markers or directives for the agent to treat this ingested content as untrusted data.\n- [EXTERNAL_DOWNLOADS]: The skill references official syntax and function documentation from Qlik's help portal (help.qlik.com). These links point to well-known and trusted service documentation.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 7, 2026, 08:48 AM
Security Audit — agent-trust-hub — qlik-load-script