protheus-business
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a lookup strategy in
reference.mdthat directs the agent to fetch external content fromtdn.totvs.comusing web search and browser automation tools. This behavior establishes a surface for indirect prompt injection, as content retrieved from the external site could contain instructions intended to manipulate the agent's behavior. - Ingestion points: Technical data and documentation fetched from
tdn.totvs.comviaWebSearch,WebFetch, and Playwright browser tools (e.g.,browser_snapshot). - Boundary markers: The skill does not provide instructions for using delimiters or boundary markers to isolate or ignore potentially malicious instructions within the fetched external data.
- Capability inventory: The agent is granted capabilities to perform web searches and use browser automation tools to navigate and extract data from external websites.
- Sanitization: There is no evidence of sanitization, filtering, or validation of the content retrieved from the external source before it is processed by the agent.
Audit Metadata