sales-engineer

Pass

Audited by Gen Agent Trust Hub on Oct 1, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from external files to generate tailored demo plans, RFP responses, and technical qualification scorecards.
  • Ingestion points: The scripts scripts/demo_planner.py, scripts/rfp_analyzer.py, and scripts/technical_qualifier.py read data from files provided by the user via command-line arguments.
  • Boundary markers: The skill does not implement boundary markers or instructions to ignore embedded commands within the processed data, which could allow malicious instructions in the source files to influence the agent's behavior.
  • Capability inventory: The included Python scripts are limited to data parsing and text formatting using standard library modules. They do not perform network operations, filesystem modifications, or system command execution.
  • Sanitization: No explicit sanitization or filtering of the input data is performed before it is formatted into the generated markdown artifacts.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 1, 2026, 01:01 AM
Security Audit — agent-trust-hub — sales-engineer