plain-english-translation
Pass
Audited by Gen Agent Trust Hub on Sep 30, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process untrusted data from external sources, creating a surface for indirect prompt injection attacks. * Ingestion points: Contract text is read from local file paths using a Read tool or fetched from external URLs using a WebFetch tool as defined in Step 1. * Boundary markers: The skill lacks explicit boundary markers or instructions for the AI to ignore embedded commands within the ingested contract text. * Capability inventory: The skill utilizes tools to read files, perform network requests (WebFetch), and write files to the local filesystem. * Sanitization: There is no explicit sanitization of input text to prevent instructions within a contract from being executed by the AI agent.
Audit Metadata