create-proposal
Pass
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes sales call transcripts and client information which may originate from untrusted external sources.
- Ingestion points:
call_transcriptinput and data fetched viascripts/read_sheet.pyfrom Google Sheets. - Boundary markers: The skill uses a JSON heredoc
<<'EOF'in theSKILL.mdto pass data to the Python script, which provides a structural boundary, but no explicit instructions are present to tell the LLM to ignore instructions embedded within the transcript. - Capability inventory: The skill can perform network operations (PandaDoc API, Google Sheets API, Gmail via agent) and file writes (temporary lead JSON files).
- Sanitization: Content is structured into JSON before execution, reducing the risk of shell injection, but the LLM remains vulnerable to following instructions found inside the transcript text during the expansion phase.
- [COMMAND_EXECUTION]: The skill uses
bashto executescripts/create_proposal.pyand provides a JSON payload via stdin. This is a standard and safe method for interoperability between the agent and local scripts. - [SAFE]: The skill uses standard secret management by requiring
PANDADOC_API_KEYto be stored in a.envfile rather than hardcoding credentials. Dependencies onrequests,gspread, andgoogle-authare well-known and standard for this use case.
Audit Metadata