tenders-finder
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from multiple third-party tender portals, creating a surface for indirect prompt injection if a portal contains malicious instructions.
- Ingestion points: The skill uses
tinyfish agent runto scrape data fromgebiz.gov.sg,tendersontime.com,biddetail.com,tendersinfo.com, andglobaltenders.com(SKILL.md). - Boundary markers: The agent prompts include specific extraction tasks and a requested JSON return format, which acts as a structural boundary, though it does not explicitly instruct the agent to ignore instructions embedded in the scraped data.
- Capability inventory: The skill identifies and displays tender information; it does not possess capabilities for file writing, system modification, or subsequent network operations based on the ingested data.
- Sanitization: There is no evidence of sanitization or filtering of the scraped content (e.g., tender titles or descriptions) before it is presented to the user.
Audit Metadata