icp-builder
Pass
Audited by Gen Agent Trust Hub on Aug 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill instructions require the agent to ingest and synthesize external data sources, creating an attack surface where malicious instructions could be embedded in the processed content.
- Ingestion points: Customer interview transcripts, deal history from CRM databases, and enrichment data from third-party market research platforms are primary data sources mentioned in SKILL.md and Section 3 (Phase G) of the operational reference.
- Boundary markers: The skill lacks explicit boundary markers, delimiters, or system instructions to ignore potential commands contained within interview transcripts or external deal notes.
- Capability inventory: The skill guides the agent to perform data analysis, pattern recognition, and reporting, which utilizes the agent's core reasoning and potentially its external tool access.
- Sanitization: No sanitization or validation protocols are established for the external text data before it is interpolated into the agent's context for analysis.
Audit Metadata