integration-error-observability

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions establish a potential surface for indirect prompt injection by directing the agent to request and ingest external content.
  • Ingestion points: In the 'Clarifying questions' section of SKILL.md, the agent is directed to ask the user for a URL of existing surfaces and the contents of integration support tickets.
  • Boundary markers: The instructions do not define delimiters or explicit warnings to prevent the agent from following instructions embedded within that external data.
  • Capability inventory: The skill consists of markdown instructions without custom code, relying on the agent's default tools to process information.
  • Sanitization: No validation or sanitization logic is included in the instructions for these external inputs.
  • [SAFE]: The skill references several trusted organizations and well-known services, such as Stripe, AWS, GitHub, Vercel, Cloudflare, and Salesforce, to provide industry-standard design examples. These references are purely for informational purposes and do not involve data exfiltration or remote code execution. Furthermore, the references/visibility-surfaces.md file provides positive security guidance, mandating the unconditional redaction of credentials and the masking of sensitive data before log exposure.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — integration-error-observability