exposure-concentration-analysis
Pass
Audited by Gen Agent Trust Hub on Jun 24, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill requires the ingestion of external data files such as loan tapes and NAICS codes for analysis. This creates a theoretical surface for indirect prompt injection. However, as the skill lacks any executable capabilities, network access, or write permissions, this surface cannot be effectively exploited.
- Ingestion points: Ingests loan-level tape data, entity linkages, and NAICS/SIC codes (SKILL.md).
- Boundary markers: Instructions do not define specific delimiters to separate user data from agent instructions.
- Capability inventory: No code execution (eval/exec), subprocess spawning, or network operations are present in the skill files.
- Sanitization: No specific data validation or sanitization protocols are mentioned for the external inputs.
Audit Metadata