dunning-action-planner
Pass
Audited by Gen Agent Trust Hub on Sep 10, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external JSON cohort data, presenting a potential attack surface for instructions embedded in the data. (1) Ingestion points: SKILL.md (Step 0)
- JSON cohort input. (2) Boundary markers: No delimiters or ignore instructions are specified for the agent. (3) Capability inventory: The skill generates markdown reports and lacks shell, network, or file system tool access. (4) Sanitization: No validation or escaping is defined.
Audit Metadata