initiative-summary
Pass
Audited by Gen Agent Trust Hub on Apr 2, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The instructions and metadata are consistent with the skill's purpose. No suspicious commands, network operations, or hardcoded credentials were found.
- [PROMPT_INJECTION]: The skill processes data from the output of external tools, presenting a surface for indirect prompt injection (Category 8).
- Ingestion points: Data returned by the
list-initiativestool into theinitiativesparameter inSKILL.md. - Boundary markers: Uses the tool's JSON-array parameter structure as a delimiting boundary.
- Capability inventory: Restricted to listing and summarizing initiatives via the One Horizon MCP tools.
- Sanitization: No explicit validation or sanitization of input data is described in the instructions.
Audit Metadata