leaked-demand-recovery

Pass

Audited by Gen Agent Trust Hub on Sep 16, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from multiple external sources (mailbox threads, chat transcripts, and lead forms) to draft recovery messages. This creates a surface for indirect prompt injection where malicious content within those communications could influence the agent's drafted output.
  • Ingestion points: SKILL.md (Step 2 and 4) and references/leak-map.md identify ingestion of mailbox history, chat transcripts, and recorder notes.
  • Boundary markers: The instructions lack explicit delimiters or instructions for the agent to disregard embedded commands within the ingested data.
  • Capability inventory: The skill reads from communication systems and generates text drafts.
  • Sanitization: No sanitization or escaping of the retrieved external content is specified before interpolation into drafts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 16, 2026, 07:56 PM
Security Audit — agent-trust-hub — leaked-demand-recovery