event-sponsor-fulfillment

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured instructions for managing event sponsor fulfillment, focusing on administrative tasks and logistics.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from external sources such as sponsorship agreements and assets. While this presents an ingestion surface for potential indirect prompt injection, the skill lacks high-privilege capabilities (like network access or shell execution) that would be necessary for exploitation. This is a common architectural characteristic and not a malicious finding.
  • [EXTERNAL_DOWNLOADS]: No remote code downloads or untrusted package installations were found in the skill's instructions or scripts.
  • [CREDENTIALS_UNSAFE]: No hardcoded secrets, API keys, or private keys were identified. The skill correctly directs users to handle sensitive payment information through official liaisons.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:14 PM
Security Audit — agent-trust-hub — event-sponsor-fulfillment