enterprise-user-management-ai-system

Warn

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: MEDIUMEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The installation instructions direct users to clone a repository from an unverified GitHub account (Nareshkumar2583/Enterprise-User-Management-System-with-AI-Analytics.git). This introduces a dependency on unverified external code that is not maintained by a trusted organization or the skill author.
  • [COMMAND_EXECUTION]: The skill instructs the agent/user to execute setup commands (npm install, pip install, npm start, uvicorn main:app) on the content of the cloned repository. This sequence results in the execution of third-party code from an unverified source.
  • [INDIRECT_PROMPT_INJECTION]: The application described by the skill ingests and processes untrusted user data which is later passed to AI analytics services.
  • Ingestion points: Data enters the system through task creation (POST /api/tasks), support tickets (POST /api/tickets), and user profile updates, which are then processed by analytics endpoints in SKILL.md.
  • Boundary markers: The provided code snippets do not show any use of delimiters or instructions to ignore embedded commands when passing data to the ML service or LLM components.
  • Capability inventory: The system has capabilities to perform database operations (MongoDB), manage user authentication (JWT), and return AI-generated risk and burnout assessments.
  • Sanitization: There is no evidence of sanitization, escaping, or validation of user-provided strings before they are utilized by the AI logic in the backend or ML service.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Oct 1, 2026, 01:35 PM
Security Audit — agent-trust-hub — enterprise-user-management-ai-system