business-logic-vulnerabilities
Pass
Audited by Gen Agent Trust Hub on Jul 21, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill creates an indirect prompt injection surface by directing the agent to ingest and analyze untrusted external data, such as source code and API logs, which could contain malicious instructions designed to influence the agent.
- Ingestion points: Analysis of external codebases and network request captures as described in METHODOLOGY.md and SCENARIOS.md.
- Boundary markers: Absence of explicit instructions for the agent to use delimiters or guardrails when processing audited content.
- Capability inventory: The agent is directed to interpret complex logic and generate test cases based on the input data.
- Sanitization: No sanitization or filtering of external content is specified before the agent processes it.
- [SAFE]: The checklists and methodologies provided are standard security auditing practices and serve an educational purpose for vulnerability research.
Audit Metadata