won-deal-icp-finder

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external deal data provided in JSON or CSV format, creating an attack surface where malicious instructions could be embedded in data fields such as company names, industries, or source fields.
  • Ingestion points: Data is ingested from external files or standard input via the load_records function in scripts/analyze.py.
  • Boundary markers: The skill uses a deterministic Python script to transform raw data into a structured JSON report, providing a layer of structural separation before the AI processes the results.
  • Capability inventory: The skill relies on scripts/analyze.py for calculations. The agent environment typically includes file system access and shell capabilities which could be targeted by successful injections.
  • Sanitization: The script performs validation and cleaning on numeric inputs (amounts and dates) but does not sanitize or filter string fields against natural language instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 03:49 PM
Security Audit — agent-trust-hub — won-deal-icp-finder