account-executive

Pass

Audited by Gen Agent Trust Hub on Sep 28, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data (CSV/JSON files) representing sales opportunities and deals, creating a surface for indirect prompt injection where malicious instructions could be embedded in data fields.
  • Ingestion points: The scripts scripts/deal_scorer.py, scripts/pipeline_analyzer.py, and scripts/win_loss_analyzer.py read deal and pipeline data from files provided via the --data argument.
  • Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore or isolate natural language content found within the data files.
  • Capability inventory: The skill executes local Python scripts for data aggregation and reporting. It does not perform network operations or system-level modifications based on the scripts provided.
  • Sanitization: While numeric fields are cast to floats/integers, string content (such as deal names, notes, or loss reasons) is interpolated directly into the generated reports without sanitization or escaping.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 28, 2026, 07:28 AM
Security Audit — agent-trust-hub — account-executive