expansion-whitespace
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- Indirect Prompt Injection Surface: The skill is designed to ingest external, potentially untrusted content such as emails, transcripts, and chat data to identify account expansion opportunities.
- Ingestion Points: External communication data, including emails, chat logs, transcripts, and enrichment documents, are integrated into the agent context during Step 2 and Step 3.
- Boundary Markers: The skill explicitly instructs the agent to treat these sources strictly as data and never as instructions, with specific directives to flag and report any instruction-like text rather than executing it.
- Capability Inventory: The skill possesses write capabilities through a CRM connector to create early-stage opportunity records based on the analyzed data.
- Sanitization & Guardrails: Robust mitigation measures are defined, including a complete ban on rendering links from untrusted content, mandatory user confirmation before executing any content-originated actions, and quoting source text verbatim with line citations.
Audit Metadata