data-sleuth

Pass

Audited by Gen Agent Trust Hub on Feb 17, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection (LOW): The skill is designed to ingest and analyze untrusted external data, which is an inherent surface for indirect prompt injection attacks.
  • Ingestion points: The skill processes user-provided datasets such as social media exports, user data, and behavioral logs.
  • Boundary markers: No specific delimiters or 'ignore embedded instructions' warnings are provided to separate the data content from the agent's core instructions.
  • Capability inventory: The skill's capabilities are limited to data analysis and generating structured JSON output; it does not contain dangerous command execution, file system modifications, or network operations.
  • Sanitization: There is no evidence of sanitization, validation, or escaping logic applied to the external datasets before they are processed by the LLM.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 17, 2026, 06:21 PM