agency-pipeline

Pass

Audited by Gen Agent Trust Hub on Sep 18, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes shell commands (ls, grep) to discover, list, and filter Markdown files within the current working directory for processing.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and parse content from external Markdown files in the local workspace, which creates a surface for indirect prompt injection.
  • Ingestion points: The skill performs a directory-wide scan for all .md files and reads their content to extract prospect data, scores, and metadata (Steps 1 and 2).
  • Boundary markers: The instructions do not define specific delimiters or "ignore embedded instructions" markers to protect the agent while it reads the content of these external files.
  • Capability inventory: The skill has the capability to execute shell commands (ls), read files from the local filesystem, and write a new consolidated report (AGENCY-PIPELINE.md) to the local filesystem.
  • Sanitization: There is no evidence of sanitization, validation, or escaping of the content read from external files before it is used in scoring calculations or written to the final output report.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 18, 2026, 07:10 AM
Security Audit — agent-trust-hub — agency-pipeline