box-automation

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface.
  • Ingestion points: The agent retrieves untrusted data from Box via tools like BOX_SEARCH_FOR_CONTENT, BOX_LIST_ITEMS_IN_FOLDER, and BOX_GET_FILE_INFORMATION.
  • Boundary markers: There are no instructions to use delimiters or ignore potentially malicious instructions embedded in the Box file data.
  • Capability inventory: The skill provides access to sensitive operations such as BOX_DELETE_FOLDER, BOX_UPLOAD_FILE, and BOX_UPDATE_COLLABORATION.
  • Sanitization: There is no mention of sanitizing or validating inputs received from the external Box service before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 04:24 PM
Security Audit — agent-trust-hub — box-automation