restaurant-online
Pass
Audited by Gen Agent Trust Hub on Jul 3, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Potential for indirect prompt injection via external web content.
- Ingestion points: The skill uses
WebSearchto gather information from Google Business Profile, Yelp, restaurant websites, and delivery platforms (Uber Eats, DoorDash, etc.) inSKILL.md. - Boundary markers: No explicit delimiters or 'ignore embedded instructions' warnings are present for the ingested data.
- Capability inventory: The agent has the capability to write a markdown report to the local filesystem (
RESTAURANT-ONLINE-[Name].md). - Sanitization: There is no evidence of input validation or sanitization for the content retrieved from web searches.
Audit Metadata