handle-objection

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • Indirect Prompt Injection Surface: The skill is designed to process untrusted external data, such as customer emails, transcripts, and external documents. This creates a potential surface for indirect prompt injection, where data might contain hidden instructions intended to redirect the agent's behavior. * Ingestion Points: The skill consumes data from emails, chat logs, transcripts, and external documentation (SKILL.md). * Boundary Markers: The skill explicitly instructs the agent to treat these inputs as data rather than instructions, to report any 'instruction-like text,' and to never render links found within them (SKILL.md). * Capability Inventory: The skill can read from CRM systems, transcripts, and documentation tools, and can draft or send emails via specific connectors like draft-outreach (SKILL.md). * Sanitization and Controls: For any action derived from this content (e.g., sending an email to a recipient named in the text), the skill requires the agent to show the full details to the user for approval before execution, regardless of the tool's default settings. It also explicitly forbids sending emails to addresses found within the untrusted text (SKILL.md).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 03:06 PM
Security Audit — agent-trust-hub — handle-objection