consultancy-practices

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Detection of an indirect prompt injection surface related to data ingestion.
  • Ingestion points: The skill ingests data from external codebase directories (defined as 'client-project/') in the SKILL.md file's integration section.
  • Boundary markers: There are no explicit delimiters or safety instructions provided to the agent to ignore instructions embedded within the codebase being analyzed.
  • Capability inventory: The skill possesses the capability to invoke other agents and tasks (e.g., 'qe-quality-analyzer', 'FleetManager') which act on the ingested data.
  • Sanitization: No evidence of sanitization, filtering, or validation of the content within the 'client-project/' scope was found.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 07:27 AM