payroll-compensation
Pass
Audited by Gen Agent Trust Hub on Mar 11, 2026
Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
- [NO_CODE]: The skill contains no executable code or scripts, consisting only of Markdown and YAML documentation for payroll processes.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection through its ingestion of external data fields in employee and contractor records.
- Ingestion points:
employee_recordandcontractor_paymentdata structures inSKILL.md. - Boundary markers: Lacks specific delimiters or instructions to ignore commands within the data fields.
- Capability inventory: Orchestrates the
salary-managementsub-skill and performs calculations. - Sanitization: No input validation or sanitization is implemented for the data fields.
Audit Metadata