won-deal-icp-finder
Pass
Audited by Gen Agent Trust Hub on Sep 21, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external deal data provided in JSON or CSV format, creating an attack surface where malicious instructions could be embedded in data fields such as company names, industries, or source fields.
- Ingestion points: Data is ingested from external files or standard input via the
load_recordsfunction inscripts/analyze.py. - Boundary markers: The skill uses a deterministic Python script to transform raw data into a structured JSON report, providing a layer of structural separation before the AI processes the results.
- Capability inventory: The skill relies on
scripts/analyze.pyfor calculations. The agent environment typically includes file system access and shell capabilities which could be targeted by successful injections. - Sanitization: The script performs validation and cleaning on numeric inputs (amounts and dates) but does not sanitize or filter string fields against natural language instructions.
Audit Metadata