autumn-concepts

Pass

Audited by Gen Agent Trust Hub on Sep 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to ingest and analyze external data, specifically a 'customer state' and 'pricing configurations,' to perform billing operations. This behavior establishes an indirect prompt injection surface where malicious or malformed input data could potentially influence the agent's reasoning and subsequent actions, such as API calls or configuration changes.
  • Ingestion points: As noted in SKILL.md, the skill is intended to be loaded and used when a 'customer state does not match the plain reading of their plan.'
  • Boundary markers: There are no explicit instructions for using delimiters or protective prompting to isolate the ingested customer data from the agent's core instructions.
  • Capability inventory: The skill guides the agent to make decisions that lead to 'writing config or calling the API' (SKILL.md).
  • Sanitization: The documentation does not provide specific procedures for validating or sanitizing the external data before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 3, 2026, 05:03 AM
Security Audit — agent-trust-hub — autumn-concepts