first-purchase-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the ae-cli tool to perform diagnostics, creating a potential surface for indirect prompt injection if the source data is attacker-controlled.
  • Ingestion points: Data retrieved via ae-cli analysis dashboard-report-data run and ae-cli analysis adhoc run as described in references/workflow-phases12.md.
  • Boundary markers: Absent. The instructions do not specify using delimiters or explicit instructions to ignore content within the data.
  • Capability inventory: The agent has the ability to write reports and create dashboards via ae-cli analysis report create and ae-cli analysis dashboard create in SKILL.md.
  • Sanitization: Absent. The skill does not define methods for sanitizing or validating external data before interpretation.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 8, 2026, 03:22 AM
Security Audit — agent-trust-hub — first-purchase-analysis