close-plan

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • Processing of Untrusted External Content: The skill is designed to ingest data from transcripts, emails, and documents (Ingestion points). It includes explicit instructions to treat this information solely as data and to ignore any embedded commands or instructions (Boundary markers). This approach proactively addresses the risk of indirect prompt injection by ensuring external content does not override the agent's core behavior.
  • Protection Against Content-Originated Actions: The skill possesses capabilities to update CRM records, create documents, and send emails (Capability inventory). To manage these capabilities safely, it requires mandatory user review for 'content-originated actions' where parameters like recipients or content are dictated by untrusted text (Sanitization). It also prohibits rendering links found within untrusted content, requiring direct links to records instead.
  • Data Access and Transparency: The skill mandates citing every value used and providing links to source records. It also enforces a strict policy against silently widening the scope to organization-wide data, requiring the agent to stop and ask for specific scopes if none are provided.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:05 PM
Security Audit — agent-trust-hub — close-plan