fit-gap-analysis
Pass
Audited by Gen Agent Trust Hub on Aug 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external 'target' documents such as RFPs, competitor visions, and specifications, which are ingestion points for untrusted data. While the instructions do not include specific delimiters or boundary markers for these inputs, the core principle of grounding all findings in the 'live system ground truth' (Step 3 and Step 4) acts as a significant mitigation against following potentially malicious instructions embedded in target documents.
- [DYNAMIC_EXECUTION]: In Step 3, the skill suggests that the agent should 'Script it if it repeats' for extracting live structural ground truth (e.g., querying information_schema). This represents a capability for generating simple scripts to automate data collection, which is a standard practice for large-scale system audits and technical assessments.
Audit Metadata