Plan March Break
Pass
Audited by Gen Agent Trust Hub on May 16, 2026
Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSNO_CODE
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection as it processes untrusted data from external PDFs and web sources to identify break dates.
- Ingestion points: External school calendar PDFs downloaded from web searches or provided via user URLs (Step 1, Tier 2 and 3).
- Boundary markers: Absent; there are no instructions to delimit the external content or warn the agent to ignore instructions embedded within the files.
- Capability inventory: The agent can read/write local files (family profiles, schedules, budget logs) and invoke related planning skills.
- Sanitization: No validation or sanitization process is described for the data extracted from the external calendar files.
- [EXTERNAL_DOWNLOADS]: The workflow involves downloading school calendars from the internet to accurately determine holiday schedules. While these are typically from public school boards, the injection risk remains.
- [NO_CODE]: The skill contains no executable code or bundled scripts, functioning instead as a set of procedural instructions for the agent.
- [COMMAND_EXECUTION]: The instructions reference internal scheduling scripts and budget calculators that are part of the local environment.
Audit Metadata