scenario-creator

Pass

Audited by Gen Agent Trust Hub on Jul 5, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill implements a workflow that is susceptible to Indirect Prompt Injection (Category 8) due to its reliance on untrusted external data for prompt generation. \n
  • Ingestion points: As described in Step 3, the agent fetches and extracts information from user-provided URLs and external tools like CRM records, meeting transcripts (e.g., Gong), or Notion pages. \n
  • Boundary markers: The instructions lack guidance for the agent to use boundary markers or safety delimiters when incorporating this external content into the new scenario. \n
  • Capability inventory: The skill leverages the ttai:create_scenario tool to deploy the generated instructions and rubrics. \n
  • Sanitization: There is no requirement for the agent to sanitize or validate the extracted content before it is used to build the scenario's ai_instructions and rubrik fields. \n- [EXTERNAL_DOWNLOADS]: The agent configuration specifies a connection to an external MCP server at https://api.toughtongueai.com/api/public/mcp. This server is hosted by the vendor and provides the necessary tools for scenario management.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 5, 2026, 06:37 PM
Security Audit — agent-trust-hub — scenario-creator