lyt
Pass
Audited by Gen Agent Trust Hub on Sep 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process various types of external, untrusted data including user-provided text, images, screenshots, CSV/XLSX spreadsheets, and PDF documents. * Ingestion points: Data enters the system via multiple channels described in SKILL.md and common-rules.md, including file uploads (PDF, XLSX) and visual media (screenshots). * Boundary markers: The provided instructions do not include specific delimiters or explicit warnings to the agent to ignore instructions embedded within the processed data formats. * Capability inventory: The skill routes these inputs to specialized sub-skills which perform complex business logic and data extraction based on the content of the untrusted data. * Sanitization: There are no documented mechanisms for sanitizing or filtering instructions that might be hidden in document metadata, image OCR text, or spreadsheet cells.
Audit Metadata