create-proposal

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes sales call transcripts and client information which may originate from untrusted external sources.
  • Ingestion points: call_transcript input and data fetched via scripts/read_sheet.py from Google Sheets.
  • Boundary markers: The skill uses a JSON heredoc <<'EOF' in the SKILL.md to pass data to the Python script, which provides a structural boundary, but no explicit instructions are present to tell the LLM to ignore instructions embedded within the transcript.
  • Capability inventory: The skill can perform network operations (PandaDoc API, Google Sheets API, Gmail via agent) and file writes (temporary lead JSON files).
  • Sanitization: Content is structured into JSON before execution, reducing the risk of shell injection, but the LLM remains vulnerable to following instructions found inside the transcript text during the expansion phase.
  • [COMMAND_EXECUTION]: The skill uses bash to execute scripts/create_proposal.py and provides a JSON payload via stdin. This is a standard and safe method for interoperability between the agent and local scripts.
  • [SAFE]: The skill uses standard secret management by requiring PANDADOC_API_KEY to be stored in a .env file rather than hardcoding credentials. Dependencies on requests, gspread, and google-auth are well-known and standard for this use case.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:55 PM