exposure-concentration-analysis

Pass

Audited by Gen Agent Trust Hub on Jun 24, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill requires the ingestion of external data files such as loan tapes and NAICS codes for analysis. This creates a theoretical surface for indirect prompt injection. However, as the skill lacks any executable capabilities, network access, or write permissions, this surface cannot be effectively exploited.
  • Ingestion points: Ingests loan-level tape data, entity linkages, and NAICS/SIC codes (SKILL.md).
  • Boundary markers: Instructions do not define specific delimiters to separate user data from agent instructions.
  • Capability inventory: No code execution (eval/exec), subprocess spawning, or network operations are present in the skill files.
  • Sanitization: No specific data validation or sanitization protocols are mentioned for the external inputs.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 24, 2026, 04:57 AM
Security Audit — agent-trust-hub — exposure-concentration-analysis