variance-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of data from external, untrusted sources by providing instructions to scrape report URLs. This introduces a surface area for indirect prompt injection, where malicious content embedded in the source reports could potentially attempt to override agent instructions.
- Ingestion points: The skill uses
context_dev_scrape_markdownandcontext_dev_extract_structured_datato process content from user-supplied report URLs, as defined inreferences/sandbase-api-map.md. - Boundary markers: The instructions do not define specific delimiters or safety prompts to isolate the scraped content from the agent's core analysis logic.
- Capability inventory: The skill utilizes
sandbase_call_toolto interact with financial data and provides extensive logic for narrative generation and management reporting. - Sanitization: There are no documented procedures for sanitizing or validating the contents of the report URLs before the data is integrated into the prompt context.
Audit Metadata