application-scope
Pass
Audited by Gen Agent Trust Hub on Apr 9, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: Indirect Prompt Injection Surface.
- Ingestion points: The
SN-Query-Tabletool reads data fromsys_app,sys_update_set, andsys_user_preferencetables inSKILL.md. - Boundary markers: There are no explicit delimiters or instructions for the agent to ignore potential instructions embedded within the retrieved ServiceNow records.
- Capability inventory: The skill possesses administrative capabilities including
SN-Set-Current-Application,SN-Create-Record, andBashaccess as defined inSKILL.md. - Sanitization: The skill does not implement validation or sanitization of record content before it enters the agent's context.
Audit Metadata