deal-advance-gap

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Untrusted Content Ingestion (Indirect Prompt Injection): The skill processes data from emails, chat transcripts, and external documents, which are potential vectors for indirect prompt injection. However, it incorporates strong defensive instructions to treat this content strictly as data, ignore embedded commands, and avoid rendering links found within these sources.
  • Ingestion points: Processes external data from emails, chats, and transcripts during the deal state gathering phase (Step 2).
  • Boundary markers: Includes explicit instructions to treat external content as data only and to report but not act on instruction-like text.
  • Capability inventory: Reads CRM records and communicates with users via artifacts; updates are handed off to specific tools like update-opportunity.
  • Sanitization: Employs logical sanitization by preventing the rendering of external links and requiring user approval for all content-originated actions.
  • Least Privilege and Scope Control: The skill implements a strict data scope, preventing automatic widening to organization-wide access and ensuring the agent operates within the user's authorized context.
  • Human-in-the-loop for Writes: All suggested CRM updates derived from analysis are presented as proposals, requiring explicit user confirmation before execution through authorized connector tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:06 PM
Security Audit — agent-trust-hub — deal-advance-gap