icp-builder

Pass

Audited by Gen Agent Trust Hub on Aug 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and synthesize external data sources, creating an attack surface where malicious instructions could be embedded in the processed content.
  • Ingestion points: Customer interview transcripts, deal history from CRM databases, and enrichment data from third-party market research platforms are primary data sources mentioned in SKILL.md and Section 3 (Phase G) of the operational reference.
  • Boundary markers: The skill lacks explicit boundary markers, delimiters, or system instructions to ignore potential commands contained within interview transcripts or external deal notes.
  • Capability inventory: The skill guides the agent to perform data analysis, pattern recognition, and reporting, which utilizes the agent's core reasoning and potentially its external tool access.
  • Sanitization: No sanitization or validation protocols are established for the external text data before it is interpolated into the agent's context for analysis.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 28, 2026, 03:31 AM
Security Audit — agent-trust-hub — icp-builder