agency-client

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and summarize content from various external files (reports, audits, and proposals) generated by different tool suites. This creates a surface for indirect prompt injection if those files contain untrusted content.
  • Ingestion points: Step 2 (Grep search across all .md and .json files) and Step 3 (Data extraction from specific patterns like AGENCY-ONBOARD-*.md).
  • Boundary markers: Absent. The skill does not define specific delimiters or instructions to the agent to disregard embedded commands within the files it reads.
  • Capability inventory: The skill is restricted to file system reading (Glob/Grep) and terminal output.
  • Sanitization: The normalization process in Step 1 (stripping special characters) provides basic protection against common injection characters for the search phase, but no sanitization is applied to the content extracted from the files themselves.
  • [DATA_EXFILTRATION]: The skill performs broad content searches across the current working directory, which may include any .md or .json files.
  • Evidence: Step 2, point 2 instructs the agent to search for client name variants in all .json and .md files in the directory. While this could include files not intended for the report, the skill only outputs to the terminal and has no network exfiltration capabilities, maintaining a local-only scope.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:10 AM
Security Audit — agent-trust-hub — agency-client