NYC

data-engineer

Fail

Audited by Gen Agent Trust Hub on Feb 15, 2026

Risk Level: HIGHPROMPT_INJECTIONNO_CODE
Full Analysis
  • [Indirect Prompt Injection] (HIGH): The skill's architectural design creates a surface where malicious instructions in external data could influence agent actions. 1. Ingestion points: External APIs (Stripe) and raw data logs as described in README.md. 2. Boundary markers: None identified in the documentation. 3. Capability inventory: manifest.yaml confirms privileges for 'modifies_files' and 'creates_artifacts'. 4. Sanitization: README mentions Zod for schema validation, but data-level validation does not reliably prevent instruction-based prompt injection.
  • [No Executable Code] (LOW): The skill consists only of documentation and a manifest. No scripts or dependency files were provided for a full technical audit of implementation-level vulnerabilities.
Recommendations
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Feb 15, 2026, 10:29 PM