internal-deadline-tracker

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill is designed to fetch and process untrusted content from external URLs, which creates a surface for indirect prompt injection.
  • Ingestion points: The skill explicitly instructs the agent to use WebSearch and WebFetch to confirm information from official Funding Agency (FA) URLs and internal institutional notices (File: SKILL.md, Steps 1 and 2).
  • Boundary markers: There are no boundary markers or instructions to the agent to treat the fetched content as potentially untrustworthy or to disregard instructions embedded within that data.
  • Capability inventory: The skill uses the Write tool to generateToDo lists, email reminders, and risk assessments, and the Bash tool for formatting and calculating dates. An attacker could potentially influence these outputs by placing malicious instructions on the pages the skill is expected to fetch.
  • Sanitization: The instructions provide no mechanism for sanitizing or validating external content before it is used to generate text or perform calculations.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 03:36 AM
Security Audit — agent-trust-hub — internal-deadline-tracker