first-purchase-analysis
Pass
Audited by Gen Agent Trust Hub on Sep 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from the
ae-clitool to perform diagnostics, creating a potential surface for indirect prompt injection if the source data is attacker-controlled. - Ingestion points: Data retrieved via
ae-cli analysis dashboard-report-data runandae-cli analysis adhoc runas described inreferences/workflow-phases12.md. - Boundary markers: Absent. The instructions do not specify using delimiters or explicit instructions to ignore content within the data.
- Capability inventory: The agent has the ability to write reports and create dashboards via
ae-cli analysis report createandae-cli analysis dashboard createinSKILL.md. - Sanitization: Absent. The skill does not define methods for sanitizing or validating external data before interpretation.
Audit Metadata