map
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [SAFE]: The skill serves as an organizational directory, mapping job descriptions to specific internal tools. It does not perform network operations, file modifications, or system-level commands.
- [INDIRECT_PROMPT_INJECTION]: The skill provides a surface for indirect prompt injection by accepting user-supplied task descriptions to determine routing. * Ingestion points: User input enters via the
argument-hintdefined inSKILL.md. * Boundary markers: The instructions do not define delimiters to isolate user input from the routing logic. * Capability inventory: The skill is limited to calling theSkilltool for redirection. * Sanitization: No specific input sanitization is implemented within the skill logic.
Audit Metadata