lyt-data-analysis

Pass

Audited by Gen Agent Trust Hub on Sep 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is configured to ingest and analyze untrusted data from multiple external sources, creating a potential attack surface for indirect prompt injection.\n
  • Ingestion points: Defined in SKILL.md and references/data-quality.md, the skill accepts CSV/XLSX tables, PDF reports, and image screenshots from third-party tools like FastMoss.\n
  • Boundary markers: While SKILL.md instructs the agent to retain raw identifiers without modification, it lacks robust delimiters or explicit instructions to ignore embedded commands within the processed data.\n
  • Capability inventory: The skill utilizes the agent's analytical reasoning and suggests the use of "script calculations" (e.g., via a Python interpreter tool) to process datasets in references/data-quality.md.\n
  • Sanitization: The instructions focus on data quality and calibration (口径校验) but do not specify technical sanitization or filtering for malicious instructions embedded in the file content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 5, 2026, 12:24 PM
Security Audit — agent-trust-hub — lyt-data-analysis