monthly-report
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted release note data from external files or user input, which acts as a potential surface for indirect prompt injection.
- Ingestion points: The skill reads raw content from
tmp/work/i/<month>.mdand accepts content pasted directly by users. - Boundary markers: There are no explicit instructions or delimiters defined to isolate the input data from the agent's instructions, though the extraction logic in Step 1 serves as an implicit filter.
- Capability inventory: The skill has permissions to read and write files within the
tmp/work/directory. - Sanitization: No specific sanitization or validation of the input content is performed prior to processing.
Audit Metadata