skills/leonardo-picciani/senior-erp-agent-skills/senior-erp-pedido-venda-consultar-status/Gen Agent Trust Hub
senior-erp-pedido-venda-consultar-status
Warn
Audited by Gen Agent Trust Hub on Feb 17, 2026
Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
- [Metadata Poisoning] (MEDIUM): The metadata field 'generated_with' claims 'OpenAI GPT-5.2', which is a non-existent version, indicating deceptive or inaccurate metadata.
- [Data Exposure & Exfiltration] (LOW): The skill uses environment variables for Bearer tokens and Client IDs, which is a standard practice, but requires secure agent configuration to prevent credential leakage.
- [Indirect Prompt Injection] (LOW): The skill ingests data from external ERP responses. 1. Ingestion points: Sales order data from Senior ERP API response fields. 2. Boundary markers: Absent. 3. Capability inventory: HTTP GET requests via cURL. 4. Sanitization: Not specified.
- [Unverifiable Dependencies] (LOW): References an external local file 'references/REFERENCE.md' that is not included in the provided source code, preventing full verification of security protocols.
Audit Metadata