revenue-operations
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted external data, including CRM notifications, signed contracts, and renewal schedules, which constitutes a potential attack surface. \n
- Ingestion points:
SKILL.md(Sections 1.1 and 5) defines inputs for deal data and renewal pipelines. \n - Boundary markers: No explicit delimiters or instructions are provided to the agent to distinguish between data and instructions within these inputs. \n
- Capability inventory: The skill does not contain executable code, subprocess calls, or network operations that could be exploited via injection. \n
- Sanitization: There are no instructions for sanitizing or validating the content of the ingested financial documents.
Audit Metadata