summarize
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize untrusted data from external sources such as URLs and PDFs, creating a surface for indirect prompt injection.\n- Ingestion points: The workflow in SKILL.md fetches content from arbitrary URLs provided by the user.\n- Boundary markers: Absent. There are no instructions to the agent to ignore or delimit instructions contained within the fetched content.\n- Capability inventory: The skill relies on fetch tools to bring external data into the agent context.\n- Sanitization: Absent. The fetched content is processed without validation or filtering.
Audit Metadata