booking
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill provides legitimate travel planning instructions and does not contain malicious code, hidden payloads, or unauthorized network operations.
- [INDIRECT_PROMPT_INJECTION]: The skill processes data from external hotel websites and search results, which is a necessary part of its core functionality.
- Ingestion points: Web search results from Booking.com and various official hotel domains (Step 2, 3, and 4).
- Boundary markers: Absent; the skill does not explicitly instruct the agent to ignore instructions within the retrieved web content.
- Capability inventory: Web search tool invocation and natural language processing of external data.
- Sanitization: Absent; the agent is expected to parse search results directly to extract price, availability, and amenities.
Audit Metadata