initiative-summary

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [SAFE]: The instructions and metadata are consistent with the skill's purpose. No suspicious commands, network operations, or hardcoded credentials were found.
  • [PROMPT_INJECTION]: The skill processes data from the output of external tools, presenting a surface for indirect prompt injection (Category 8).
  • Ingestion points: Data returned by the list-initiatives tool into the initiatives parameter in SKILL.md.
  • Boundary markers: Uses the tool's JSON-array parameter structure as a delimiting boundary.
  • Capability inventory: Restricted to listing and summarizing initiatives via the One Horizon MCP tools.
  • Sanitization: No explicit validation or sanitization of input data is described in the instructions.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 10:13 AM