skills/uipath/skills/uipath-planner/Gen Agent Trust Hub

uipath-planner

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill's primary function involves parsing untrusted external process documentation to derive implementation plans. This creates a significant surface for indirect prompt injection attacks.
  • Ingestion points: The skill reads data from various untrusted formats including Word (.docx), PDF, and Markdown files using the Read tool, and fetches remote content from wikis or SharePoint via WebFetch (as detailed in the PDD Analysis Guide).
  • Boundary markers: While the skill's remediation guidance suggests using delimiters and 'ignore embedded instructions' warnings for external content, the instructions do not strictly enforce these boundaries during the data extraction and templating process.
  • Capability inventory: The skill possesses capabilities that could be abused if an injection is successful, including the ability to write files to the filesystem (Write), execute local conversion scripts (Bash), and create tasks (TaskCreate) that are automatically executed by other specialist agents.
  • Sanitization: There is no explicit step to sanitize or filter natural language instructions from ingested documents before they are used to populate solution templates or task prompts.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 06:04 PM
Security Audit — agent-trust-hub — uipath-planner