procurement-docs

Pass

Audited by Gen Agent Trust Hub on Jul 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill is designed to ingest and process user-supplied content to generate procurement specifications and contract reviews.
  • Ingestion points: User-provided 'Existing documents' are ingested during the preparation phase in 'skill.md'.
  • Boundary markers: No explicit delimiters or instructions are used to separate untrusted document content from the agent's system instructions.
  • Capability inventory: The skill has the capability to write multiple files to the local filesystem within the '_workspace/' directory.
  • Sanitization: There is no evidence of content validation or sanitization to prevent embedded instructions from being executed by the collaborating agents.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 26, 2026, 08:16 PM
Security Audit — agent-trust-hub — procurement-docs