senior-erp-pedido-venda-consultar-status

Warn

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: MEDIUMCOMMAND_EXECUTION
Full Analysis
  • [Metadata Poisoning] (MEDIUM): The metadata field 'generated_with' claims 'OpenAI GPT-5.2', which is a non-existent version, indicating deceptive or inaccurate metadata.
  • [Data Exposure & Exfiltration] (LOW): The skill uses environment variables for Bearer tokens and Client IDs, which is a standard practice, but requires secure agent configuration to prevent credential leakage.
  • [Indirect Prompt Injection] (LOW): The skill ingests data from external ERP responses. 1. Ingestion points: Sales order data from Senior ERP API response fields. 2. Boundary markers: Absent. 3. Capability inventory: HTTP GET requests via cURL. 4. Sanitization: Not specified.
  • [Unverifiable Dependencies] (LOW): References an external local file 'references/REFERENCE.md' that is not included in the provided source code, preventing full verification of security protocols.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 17, 2026, 12:30 AM