agent-cost-optimization-analyst

Pass

Audited by Gen Agent Trust Hub on Mar 5, 2026

Risk Level: SAFEPROMPT_INJECTIONNO_CODE
Full Analysis
  • [PROMPT_INJECTION]: The skill possesses an indirect prompt injection surface as it is designed to ingest and analyze potentially untrusted external data.
  • Ingestion points: Processes documents such as financial statements, vendor contracts, and cloud utilization reports.
  • Boundary markers: No delimiters or instructions to ignore embedded commands are present in the prompt.
  • Capability inventory: The agent is equipped with high-privilege tools including Bash, Write, Edit, and WebFetch (SKILL.md).
  • Sanitization: No evidence of input validation or sanitization is present.
  • [NO_CODE]: No executable script files (e.g., Python, JavaScript, or Shell) were provided for analysis beyond the instructional markdown and configuration metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 5, 2026, 01:13 AM