vendor-check

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [Indirect Prompt Injection Surface]: The skill is designed to ingest and process information from external, potentially untrusted sources such as emails, chat messages, and document storage. This creates a surface where the agent could encounter malicious instructions embedded within legitimate-looking data (e.g., a hidden prompt in a vendor's email attachment).
  • Ingestion points: Data is retrieved from CLM, CRM, Email systems, document storage (Box/SharePoint), and Chat platforms (Slack/Teams) during the 'Search Connected Systems' phase (Step 2).
  • Boundary markers: The instructions do not specify the use of clear delimiters or instructions to the model to ignore potential commands embedded within the retrieved text.
  • Capability inventory: The skill's primary capabilities are data retrieval, search, and report generation based on the aggregated findings.
  • Sanitization: No explicit sanitization or filtering of the retrieved content is mentioned before it is processed into the final report summary.
  • [Access to Sensitive Data]: The skill's primary purpose involves accessing and summarizing highly sensitive legal and business information, including MSAs, DPAs, and financial terms. While this is the intended functionality, it requires the agent to have broad read access across many organizational silos.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 11:26 PM
Security Audit — agent-trust-hub — vendor-check