cite-compare
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill exhibits a potential surface for indirect prompt injection due to its research-focused functionality.
- Ingestion points: External data is introduced into the agent context via
WebSearchandWebFetchtools during the jurisdictional research phase (Step 1). - Boundary markers: The instructions lack specific delimiters or warnings to the model to ignore embedded instructions within the fetched regulatory guidance.
- Capability inventory: The skill's execution environment includes the
BashandWritetools, which could potentially be targeted if an injection occurs. - Sanitization: No explicit sanitization or content validation steps are defined for the data retrieved from the web before it is processed for the final artifact.
Audit Metadata