lab-safety-intake
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection due to its core function of processing external research data.
- Ingestion points: The skill uses the
Readtool to ingest external data including research plans, experiment plans, SOPs, and approval documents as specified in the 'Required Inputs' section of SKILL.md. - Boundary markers: There are no explicit instructions or delimiters defined to isolate the ingested research data from the agent's primary instructions.
- Capability inventory: The skill has access to
Write(to create confirmation sheets and emails),Bash(for formatting tables), andWebSearch(to look up institutional safety info). - Sanitization: No input sanitization or validation logic is present to filter malicious instructions embedded within the ingested laboratory documents.
Audit Metadata