account-context
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill accesses data through several ingestion points including email, chat history, and meeting transcripts (SKILL.md), which are external and potentially untrusted.
- Boundary Markers: The instructions include clear boundary markers, directing the agent to treat external content as data only and to report any instruction-like text rather than acting on it.
- Capability Inventory: The skill has the capability to read CRM and documentation data and post messages to internal chat channels.
- Sanitization and Review: The skill mitigates risks by preventing the rendering of external links and by requiring explicit human review for any action suggested by the content of the untrusted sources.
Audit Metadata