case-study-publisher

Pass

Audited by Gen Agent Trust Hub on Apr 13, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted text from a user-filled intake form and uses it to perform actions on several platforms. 1. Ingestion points: Intake form sections for headlines, capability paragraphs, and pull quotes. 2. Boundary markers: No clear delimiters are used to separate user data from instructions. 3. Capability inventory: The agent uses javascript_tool and form_input for browser automation and can post to Slack. 4. Sanitization: No security sanitization is performed on user inputs.
  • [EXTERNAL_DOWNLOADS]: The skill downloads content from user-provided URLs (customer logos) to process them in Google Slides, which involves fetching data from arbitrary external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 13, 2026, 01:21 PM