vendor-risk-kyc-screening
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill consists solely of natural language instructions for research tasks. It does not include any scripts, binary files, or executable commands.
- [PROMPT_INJECTION]: The skill's primary function is to ingest untrusted data from external search results and web pages, which presents a surface for indirect prompt injection.
- Ingestion points: External web content retrieved via search, extract, map, and crawl tools referenced in SKILL.md.
- Boundary markers: No delimiters or specific instructions to ignore embedded commands are present in the workflow.
- Capability inventory: The skill utilizes search and extraction capabilities to gather information.
- Sanitization: No explicit sanitization or filtering of external content is described in the research process.
Audit Metadata