lodge-recon
Pass
Audited by Gen Agent Trust Hub on Jul 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it is designed to ingest and process untrusted data from the internet.
- Ingestion points: External regulatory guidance and project-specific documents fetched via WebSearch and WebFetch tools in Step 1.
- Boundary markers: Absent; there are no instructions provided to the agent to ignore or delimit instructions found within the externally retrieved data.
- Capability inventory: The skill has access to potentially dangerous tools including Bash, Write, and WebFetch across its operational steps.
- Sanitization: Absent; the instructions do not specify any validation, filtering, or escaping of the content retrieved from external sources before it is processed by the agent.
Audit Metadata