application-scope

Pass

Audited by Gen Agent Trust Hub on Apr 9, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface.
  • Ingestion points: The SN-Query-Table tool reads data from sys_app, sys_update_set, and sys_user_preference tables in SKILL.md.
  • Boundary markers: There are no explicit delimiters or instructions for the agent to ignore potential instructions embedded within the retrieved ServiceNow records.
  • Capability inventory: The skill possesses administrative capabilities including SN-Set-Current-Application, SN-Create-Record, and Bash access as defined in SKILL.md.
  • Sanitization: The skill does not implement validation or sanitization of record content before it enters the agent's context.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 9, 2026, 02:38 PM