protheus-business

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a lookup strategy in reference.md that directs the agent to fetch external content from tdn.totvs.com using web search and browser automation tools. This behavior establishes a surface for indirect prompt injection, as content retrieved from the external site could contain instructions intended to manipulate the agent's behavior.
  • Ingestion points: Technical data and documentation fetched from tdn.totvs.com via WebSearch, WebFetch, and Playwright browser tools (e.g., browser_snapshot).
  • Boundary markers: The skill does not provide instructions for using delimiters or boundary markers to isolate or ignore potentially malicious instructions within the fetched external data.
  • Capability inventory: The agent is granted capabilities to perform web searches and use browser automation tools to navigate and extract data from external websites.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the content retrieved from the external source before it is processed by the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 11:02 AM
Security Audit — agent-trust-hub — protheus-business