threat-intelligence-enrichment
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted data from external security sources such as web search results, vendor advisories, and research blogs.
- Ingestion points: Data retrieved from the internet via search and extraction tools (SKILL.md).
- Boundary markers: There are no explicit delimiters or instructions to treat external content as untrusted data rather than instructions.
- Capability inventory: The skill uses search, extract, and crawl capabilities to gather and synthesize information.
- Sanitization: The skill lacks specific validation or sanitization steps for the content retrieved from external URLs before it is processed by the agent.
Audit Metadata