churn-lost-deal-analysis

Pass

Audited by Gen Agent Trust Hub on Apr 2, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill retrieves and processes untrusted text data from CRM deal notes, call notes, and comments, which creates a surface for indirect prompt injection attacks. Malicious instructions embedded in these CRM fields could be executed by the agent or bias the generated report.\n
  • Ingestion points: Deal notes, call notes, and comments from the CRM specified in {{CRM_NAME}} (SKILL.md).\n
  • Boundary markers: Absent; the template does not use delimiters to isolate retrieved data from agent instructions.\n
  • Capability inventory: Reading CRM data and writing files to Google Drive (SKILL.md).\n
  • Sanitization: Absent; no validation or filtering of external content is specified before processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 2, 2026, 08:18 PM
Security Audit — agent-trust-hub — churn-lost-deal-analysis