event-press-relations
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions define an attack surface for indirect prompt injection because the agent is directed to ingest and evaluate information from external event policy pages and user-provided descriptions of media entities without providing specific boundary markers or sanitization logic. * Ingestion points: External event policy pages (e.g., Web Summit, MWC/GSMA) and user-supplied names of media outlets and content creators (SKILL.md, references/accreditation-policy.md). * Boundary markers: The instructions do not define explicit delimiters or warnings to ignore commands that may be embedded in the external data. * Capability inventory: The workflow involves information gathering to check for policy updates and verify media outlet history across all referenced files. * Sanitization: No sanitization or input validation is specified for the processed external text.
- [SAFE]: The skill primarily consists of organizational logic, policy templates, and crisis management principles for event organizers. No instances of malicious code, data exfiltration, hardcoded credentials, or persistence mechanisms were found. All external organizations referenced for industry precedent, such as PyCon US, FOSDEM, and CNCF, are well-known entities documented neutrally for context.
Audit Metadata