leiloeiro-edital
Pass
Audited by Gen Agent Trust Hub on Jun 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill is designed to ingest and analyze external auction notices (editais). This creates a risk of indirect prompt injection, where malicious instructions hidden within a notice could attempt to subvert the agent's analysis or safety protocols. \n
- Ingestion points: Auction notices and related data provided by the user (SKILL.md). \n
- Boundary markers: None; the skill directly processes external text without delimiters or isolation. \n
- Capability inventory: The skill primarily provides instructions but includes a local logging script (governance.py) that writes to the local filesystem. \n
- Sanitization: No explicit sanitization, validation, or escaping of ingested external content is implemented.
Audit Metadata