bench-it
Pass
Audited by Gen Agent Trust Hub on Aug 16, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and process data from external, untrusted sources such as competitor documentation and benchmark posts.
- Ingestion points: Public documentation, pricing pages, and public benchmark posts mentioned in the 'Outside: which outside thing?' section of SKILL.md.
- Boundary markers: Absent; the instructions do not provide delimiters or 'ignore embedded instructions' warnings for external content.
- Capability inventory: The skill is restricted to information gathering and report generation; no scripts or tools with file-system, network, or command execution capabilities are identified.
- Sanitization: Absent; the skill does not specify filtering, validation, or escaping of the gathered external content.
Audit Metadata