account-executive
Pass
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data (CSV/JSON files) representing sales opportunities and deals, creating a surface for indirect prompt injection where malicious instructions could be embedded in data fields.
- Ingestion points: The scripts
scripts/deal_scorer.py,scripts/pipeline_analyzer.py, andscripts/win_loss_analyzer.pyread deal and pipeline data from files provided via the--dataargument. - Boundary markers: No explicit delimiters or instructions are provided to the agent to ignore or isolate natural language content found within the data files.
- Capability inventory: The skill executes local Python scripts for data aggregation and reporting. It does not perform network operations or system-level modifications based on the scripts provided.
- Sanitization: While numeric fields are cast to floats/integers, string content (such as deal names, notes, or loss reasons) is interpolated directly into the generated reports without sanitization or escaping.
Audit Metadata