procurement-analysis
Pass
Audited by Gen Agent Trust Hub on Mar 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection because it is designed to ingest and analyze a wide variety of external procurement records and codebase content without pre-defined boundary markers or sanitization logic.
- Ingestion points: The skill instructions (Phase 1) direct the agent to read the codebase and comprehensive data from procurement platforms such as SAP Ariba, Coupa, and Jaggaer.
- Boundary markers: Absent. The skill does not provide specific delimiters or instructions to ignore embedded commands within the ingested data.
- Capability inventory: The skill has the capability to write reports to the 'docs/' directory and append execution metadata to 'skill-telemetry.md' in the '~/.claude/projects/' directory (Phase 7 and Telemetry sections).
- Sanitization: Absent. There is no instruction to validate or escape external content before processing.
- [SAFE]: The skill accesses sensitive financial and business data, including vendor master files (banking, tax IDs) and contract terms, which is a required function for procurement spend analytics.
- [SAFE]: The skill records execution telemetry in the '~/.claude/projects/' hidden directory. This interaction is restricted to the local environment and serves as a performance tracking and self-improvement mechanism for the agent.
Audit Metadata